Overview

  • The Singapore Police Force and the Cyber Security Agency have reported that scams involving fake job offers have resulted in losses totaling $11.8 million.
  • One victim was misled by a phony recruiter for a cryptocurrency company and directed to complete a coding assessment on a corporate laptop.
  • Malicious software captured a session token, enabling the attackers to bypass multi-factor authentication and access the victim's Bitbucket account.

According to a joint advisory from the Singapore Police Force and the Cyber Security Agency of Singapore, scammers impersonating recruiters for cryptocurrency firms have defrauded individuals of $11.8 million (S$15.1 million) through deceptive job offers that compromise their employers.

In a statement released on Friday, which was covered by The Straits Times and Channel NewsAsia, the agencies detailed how the scam operates. A victim was initially contacted on LinkedIn by someone impersonating a recruiter for a crypto company and was later moved to email, where the sender used a domain name that closely mimicked that of a legitimate firm. The victim participated in several interviews via Google Meet, during which the interviewer's camera was turned off.

The victim was subsequently directed to a fake website to complete a technical coding assessment on a company-issued device, unknowingly downloading malicious software in the process.

This malware was able to capture a session token, which is a unique string issued by a service to maintain a user's logged-in status. Since the token corresponds to an authenticated session, it allowed the attackers to bypass multi-factor authentication and gain access to the victim's Bitbucket account, used by the company for managing its source code.

Once inside, the attackers modified the employer's software systems and accessed internal servers, gathering credentials that enabled them to circumvent transaction limits and approval checks to transfer funds. The advisory did not disclose any company names, the destination of the stolen funds, or identify the perpetrators. Decrypt has reached out to LinkedIn for a statement and will provide updates if they respond.

Contagious Interviews

This type of scam has been observed in ongoing operations referred to as Contagious Interview, where fake recruiters guide Web3 developers toward malicious code, including over 300 harmful packages uploaded to the npm registry. A group known as TraderTraitor has employed fake job offers to infiltrate corporate cloud systems instead of targeting individual wallets, which one researcher noted is where significant funds are held. Others have impersonated recruiters from Coinbase and Uniswap to prompt targets to execute commands.

While these scams are often linked to North Korean hackers, the strategies are not exclusive to them. The Russian-speaking group Crazy Evil created a fictitious Web3 company, ChainSeeker.io, and advertised blockchain analyst positions to entice job seekers into installing malware that drains their wallets.

To protect themselves, the Singaporean agencies advise individuals to verify recruiters through official channels, to be cautious of interviewers who refuse to turn on their cameras, and to avoid executing code from unverified sources. For companies, it is recommended to secure API keys and internal credentials, enhance multi-factor authentication, and monitor for unfamiliar devices and unusual network activity. If a breach is suspected, they advise isolating compromised systems, revoking active sessions, resetting credentials, and reviewing access logs.

Daily Debrief Newsletter

Stay updated daily with the latest news stories, plus original features, podcasts, videos, and more.