Fake LinkedIn Crypto Job Scams Have Cost $11.8M: Singapore
Scammers posing as crypto recruiters have stolen $11.8 million in a Singapore-linked campaign by using fake job interviews to infect targets’ work devices. The attack starts on LinkedIn, moves to spoofed email and video interviews, then pushes victims to run a technical assessment on a company-issued device. That download installs malware that steals a session token, bypassing multi-factor authentication and giving access to company systems such as Bitbucket. From there, attackers modify software systems, reach internal servers, collect credentials, and move money by обходing transaction limits and approval checks. The tactic matches a broader “fake recruiter” pattern seen in crypto and Web3 attacks, including campaigns tied to North Korean and Russian-speaking groups. Advice includes verifying recruiters through official channels, avoiding code from untrusted sources, securing API keys and internal credentials, strengthening MFA, and isolating systems and revoking sessions quickly after suspected compromise.
