
Singapore police say scammers posing as crypto recruiters on LinkedIn stole $11.8M. They use fake coding tests to plant malware that bypasses MFA and targets corporate accounts.
Singapore authorities say scammers posing as cryptocurrency recruiters on LinkedIn have stolen $11.8 million (S$15.1 million) from victims by using fake job offers to compromise their employers.
The joint advisory from the Singapore Police Force and the Cyber Security Agency of Singapore, reported Friday by The Straits Times and Channel NewsAsia, laid out the mechanics. A victim gets contacted on LinkedIn by someone claiming to recruit for a crypto firm. The conversation shifts to email, where the sender uses a spoofed domain mimicking a real company. Several interviews follow on Google Meet. The interviewer keeps their camera off.
Victims are sent to a spoofed website for a technical coding assessment. They complete the test on a company-issued device, downloading malicious software without realizing it in the process.
The malware captures a session token, the string a service issues to keep a user logged in. Because the token represents an already-authenticated session, presenting it bypasses multi-factor authentication and opens the victim's Bitbucket account, where the company stores and manages source code.
Attackers then alter the employer's software systems and reach its internal servers, collecting credentials used to bypass transaction limits and approval checks and move funds, the agencies said. The advisory does not name any company, say where the funds went, or attribute the attacks to anyone. Decrypt has approached LinkedIn for comment.
The pattern is well documented. Researchers track a long-running operation called Contagious Interview, in which fake recruiters steer Web3 developers toward malicious code. That group has uploaded more than 300 booby-trapped packages to the npm registry. Another group called TraderTraitor has used fake job offers to reach corporate cloud systems rather than individual wallets, which one researcher put down to that being where the money sits. Others have posed as recruiters from Coinbase and Uniswap.
Those campaigns are attributed to North Korean hackers, the method is not uniquely theirs. The Russian-speaking crew Crazy Evil built an entire fake Web3 company, ChainSeeker.io, and advertised blockchain analyst roles to lure applicants into installing wallet-draining malware.
Singapore agencies advise individuals to verify recruiters through official channels, treat an interviewer who will not turn on their camera as a warning sign, and never run code from an unverified source. For companies, they recommend securing API keys and internal credentials, strengthening multi-factor authentication, and watching for unfamiliar devices and unusual network activity. Where a compromise is suspected, they advise isolating affected systems, revoking active sessions, resetting credentials, and reviewing access logs.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.