Fireblocks said it uncovered and stopped a hiring scam that targeted developers and technical candidates by impersonating the company’s recruiters. The operation used LinkedIn, Google Meet, and GitHub to stage convincing interview processes and trick victims into running malware on their personal machines.
Fake recruiter profiles were built to look credible
According to the report, the attackers first approached candidates on LinkedIn while posing as Fireblocks HR staff, technical recruiters, or hiring managers. The profiles were designed to look legitimate, with professional photos, realistic work histories, and established-looking networks. After contact was made, candidates received polished PDF documents and links to detailed Figma boards describing a fictional project often referred to as “Poker Platform.” The material was presented in a way that matched normal recruiting communication.
Live interviews added trust before the coding test
The scam went beyond messages and documents. Attackers also conducted live video interviews over Google Meet, discussing experience, compensation, and role expectations in a format that resembled a standard hiring process. The final step was framed as a coding assessment. Fireblocks noted that calls were often cut off abruptly, a small detail but one that appeared repeatedly in the campaign.
GitHub assignments hid the malware payload
Candidates were asked to clone GitHub repositories and run routine setup commands such as npm install. For developers, that is a normal step. In this case, it became the delivery mechanism for malware. Fireblocks said the campaign used EtherHiding, a method that relies on blockchain smart contracts to store and retrieve command-and-control infrastructure, making the malware harder to remove and harder to track.
Once executed, the malware could steal crypto wallet credentials and private keys, authentication tokens and passwords, and information tied to company development environments. The exposure was not limited to personal accounts.
The campaign matched the Contagious Interview pattern
Fireblocks said the setup, tooling, and execution resembled the “Contagious Interview” attack model, a documented social engineering pattern linked to Lazarus Group and active since 2023. The model exploits remote hiring workflows, especially cases where technical candidates are expected to run untested code as part of an interview. The article also pointed to prior reporting from MITRE ATT&CK and SentinelOne describing similar tactics against the crypto sector for financial gain and espionage.
How Fireblocks responded and what candidates should verify
The investigation began after some crypto job seekers contacted Fireblocks about a project that did not exist. The company said its security team identified the impersonation network and worked with LinkedIn and GitHub to remove fake accounts and malicious repositories. It also coordinated with intelligence partners, law enforcement, and internal threat-hunting teams.
Fireblocks said legitimate openings are listed on its official careers page, and verified recruiters use company email addresses and verified LinkedIn profiles. Its warning to candidates was direct: do not run interview code without verifying the source, even if the position, pay discussion, and interview flow appear authentic.

