Fireblocks Warns of Fake LinkedIn Recruiters Using Job Interviews to Deliver Malware

Fireblocks Warns of Fake LinkedIn Recruiters Using Job Interviews to Deliver Malware

N
News Editor 01
2026-07-23 06:15:16
Fireblocks said attackers impersonated its recruiters on LinkedIn and Google Meet, then used GitHub coding tasks to infect candidates with malware in a campaign resembling the Contagious Interview pattern linked to Lazarus Group.
FireblocksLinkedIn scammalwareLazarus Groupcybersecurity

Fireblocks said it uncovered and stopped a hiring scam that targeted developers and technical candidates by impersonating the company’s recruiters. The operation used LinkedIn, Google Meet, and GitHub to stage convincing interview processes and trick victims into running malware on their personal machines.

Fake recruiter profiles were built to look credible

According to the report, the attackers first approached candidates on LinkedIn while posing as Fireblocks HR staff, technical recruiters, or hiring managers. The profiles were designed to look legitimate, with professional photos, realistic work histories, and established-looking networks. After contact was made, candidates received polished PDF documents and links to detailed Figma boards describing a fictional project often referred to as “Poker Platform.” The material was presented in a way that matched normal recruiting communication.

Live interviews added trust before the coding test

The scam went beyond messages and documents. Attackers also conducted live video interviews over Google Meet, discussing experience, compensation, and role expectations in a format that resembled a standard hiring process. The final step was framed as a coding assessment. Fireblocks noted that calls were often cut off abruptly, a small detail but one that appeared repeatedly in the campaign.

GitHub assignments hid the malware payload

Candidates were asked to clone GitHub repositories and run routine setup commands such as npm install. For developers, that is a normal step. In this case, it became the delivery mechanism for malware. Fireblocks said the campaign used EtherHiding, a method that relies on blockchain smart contracts to store and retrieve command-and-control infrastructure, making the malware harder to remove and harder to track.

Once executed, the malware could steal crypto wallet credentials and private keys, authentication tokens and passwords, and information tied to company development environments. The exposure was not limited to personal accounts.

The campaign matched the Contagious Interview pattern

Fireblocks said the setup, tooling, and execution resembled the “Contagious Interview” attack model, a documented social engineering pattern linked to Lazarus Group and active since 2023. The model exploits remote hiring workflows, especially cases where technical candidates are expected to run untested code as part of an interview. The article also pointed to prior reporting from MITRE ATT&CK and SentinelOne describing similar tactics against the crypto sector for financial gain and espionage.

How Fireblocks responded and what candidates should verify

The investigation began after some crypto job seekers contacted Fireblocks about a project that did not exist. The company said its security team identified the impersonation network and worked with LinkedIn and GitHub to remove fake accounts and malicious repositories. It also coordinated with intelligence partners, law enforcement, and internal threat-hunting teams.

Fireblocks said legitimate openings are listed on its official careers page, and verified recruiters use company email addresses and verified LinkedIn profiles. Its warning to candidates was direct: do not run interview code without verifying the source, even if the position, pay discussion, and interview flow appear authentic.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.