Sophisticated Job Scam Targets Web3 Community with Malware Disguised as AI Software
Security analysts at SlowMist have uncovered a targeted phishing campaign exploiting the hiring process in the blockchain sector. Their threat intelligence platform detected malicious activity where attackers impersonate recruiters to distribute harmful software.
The Attack Vector: Fake Interviews, Real Threats
Cybercriminals approach potential victims posing as hiring managers from legitimate crypto projects or tech firms. After initial contact via professional networks, they schedule virtual interviews and insist on using a proprietary meeting application called "Relay."
This software appears as a polished AI-powered conferencing tool but contains hidden payloads. Once installed on macOS or Windows systems, it operates silently in the background while maintaining a convincing user interface.
Data Extraction Tailored for Crypto Users
Technical analysis reveals the malware's specialized data harvesting capabilities:
- Credential Theft: Extracts saved passwords and autofill data from major web browsers
- Wallet Targeting: Scans for cryptocurrency wallet extensions, seed phrases, and private key files
- System Access: Compromises macOS Keychain and monitors clipboard activity
- Communication Monitoring: Steals session data from messaging apps like Telegram
This focused approach indicates attackers have studied common security practices and digital asset storage methods within the Web3 community.
Practical Protection Measures
Professionals should adopt these defensive strategies when engaging in remote hiring processes:
- Question any interview requiring proprietary software—legitimate companies use established platforms
- Verify recruiter identities through official company channels before proceeding
- Consider using isolated devices or virtual machines for job-seeking activities
- Monitor systems for unusual network connections or resource usage
If suspicious software was installed, disconnect from the internet immediately, run comprehensive security scans, and assume credentials may be compromised.