This website uses cookies
We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you’ve provided to them or that they’ve collected from your use of their services.
Consent Selection
Details
  • Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
  • Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
    • We do not use cookies of this type.

  • Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
    • We do not use cookies of this type.

  • Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
    • We do not use cookies of this type.

  • Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    • __emg_sidPending
      Maximum Storage Duration: 1 dayType: HTTP Cookie
      __emg_vidPending
      Maximum Storage Duration: 1 yearType: HTTP Cookie
      nl-read-countPending
      Maximum Storage Duration: PersistentType: HTML Local Storage
Cookie declaration last updated on 8/12/26 by Cookiebot
[#IABV2_TITLE#]
[#IABV2_BODY_INTRO#]
[#IABV2_BODY_LEGITIMATE_INTEREST_INTRO#]
[#IABV2_BODY_PREFERENCE_INTRO#]
[#IABV2_BODY_PURPOSES_INTRO#]
[#IABV2_BODY_PURPOSES#]
[#IABV2_BODY_FEATURES_INTRO#]
[#IABV2_BODY_FEATURES#]
[#IABV2_BODY_PARTNERS_INTRO#]
[#IABV2_BODY_PARTNERS#]
About
Cookies are small text files that can be used by websites to make a user's experience more efficient.

The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission.

This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.

You can at any time change or withdraw your consent from the Cookie Declaration on our website.

Learn more about who we are, how you can contact us and how we process personal data in our Privacy Policy.

Please state your consent ID and date when you contact us regarding your consent.
NewsLayer

Install NewsLayer

Get the app experience — one tap from your home screen, instant loads and breaking-news alerts.

NewsLayer.com
External Reporting게시 4시간 전

Fake LinkedIn Crypto Job Scams Have Cost $11.8M: Singapore

Malware planted during a bogus coding assessment harvested a session token, bypassing multi-factor authentication to reach a code repository.

Fake LinkedIn Crypto Job Scams Have Cost $11.8M: Singapore
작성자 Decrypt AgentPublisher Decrypt 2 분 소요
Image via Decrypt

Layer Index

↓ 7 pts in 24h

In brief

  • Singapore's police force and cyber security agency put losses from a scam using fake job offers and compromised software systems at $11.8 million.
  • They describe a case in which a victim was approached by a bogus recruiter for a crypto firm and steered into a coding assessment run on a company laptop.
  • The malware harvested a session token, which was used to bypass multi-factor authentication and open the victim's Bitbucket account.

Scammers posing as recruiters for cryptocurrency companies have taken $11.8 million (S$15.1 million), using fake job offers to compromise their targets' employers, according to a joint advisory from the Singapore Police Force and the Cyber Security Agency of Singapore.

Setting out how the scam works in a statement on Friday, reported by The Straits Times and Channel NewsAsia, the agencies said a victim was approached on LinkedIn by someone posing as a recruiter for a crypto company, then moved to email, where the sender used a spoofed domain closely resembling a real firm's. Several interviews followed on Google Meet. The interviewer kept their camera off throughout.

The victim was then sent to a spoofed website to complete a technical coding assessment, and did so on a company-issued device, downloading malicious software in the process without realizing it.

The malware captured a session token, the string a service issues to keep a user logged in. Because the token represents an already-authenticated session, presenting it bypassed multi-factor authentication and opened the victim's Bitbucket account, where the company stores and manages its source code.

From there the attackers altered the employer's software systems and reached its internal servers, the agencies said, collecting credentials that were then used to get around transaction limits and approval checks and move funds. The advisory does not name any company, say where the funds went, or attribute the attacks to anyone. Decrypt has approached LinkedIn for comment and will update this article should they respond.

Contagious Interviews

That pattern is well documented, with researchers tracking a long-running operation they call Contagious Interview, in which fake recruiters steer Web3 developers toward malicious code, including more than 300 booby-trapped packages uploaded to the npm registry. A group known as TraderTraitor has used fake job offers to reach corporate cloud systems rather than individual wallets, which one researcher put down to that being where the money sits. Others have posed as recruiters from Coinbase and Uniswap to get targets running commands.

Those campaigns are attributed to North Korean hackers, but the playbook is not uniquely theirs. The Russian-speaking crew Crazy Evil built an entire fake Web3 company, ChainSeeker.io, and advertised blockchain analyst roles to lure applicants into installing wallet-draining malware.

Singapore agencies’ advice to individuals is to verify recruiters through official channels, treat an interviewer who will not turn on their camera as a warning sign, and never run code from an unverified source. For companies, the agencies recommend securing API keys and internal credentials, strengthening multi-factor authentication and watching for unfamiliar devices and unusual network activity. Where a compromise is suspected, they advise isolating affected systems, revoking active sessions, resetting credentials and reviewing access logs.

속보

속보를 놓치지 마세요

Advertisement

House — Advertise on NewsLayer
NewsLayerAd

Sourced by

Originally reported by Decrypt

NewsLayer coverage based on externally reported material.

The Daily Brief

The onchain economy, before your day starts.

Curated markets, onchain insights, and key headlines — delivered every weekday morning.

Weekdays · Free · ~5 minute read

관련 기사