By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Gulf PressGulf Press
  • Gulf News
    • Saudi Arabia
    • UAE
    • Oman
    • Kuwait
    • Qatar
    • Bahrain
  • Business
  • Technology
  • Real Estate
  • Sport
  • Travel
  • Lifestyle
  • Rankings
  • Explained
  • Opinion
Search
Countries
More Topics
Site Links
  • Newsletter
  • Terms
  • About Us
  • Advertise with us
  • Contact Us
© 2023 Gulf Press. All Rights Reserved.
Reading: Fraudulent Web3 Job Recruiters Enhance Their Cryptocurrency-Stealing Malware
Share
Notification Show More
Latest News
Abdullah bin Hamad Al-Attiyah 50 Years of Energy Leadership
Qatar
Two Emergency Spinal Surgeries Succeed at Rustaq Hospital
Oman
Electricity Services Committee Approves Energy Storage Sites in Al-Mutlaa and Jabir Al-Ahmad
Kuwait
Foreign Minister Strengthens Friendship and Cooperation Ties with the Philippines
Bahrain
Post-Eid Return Shock: 8 Health Issues Dragging Employee Productivity
UAE
Aa
Gulf PressGulf Press
Aa
  • Gulf News
  • Business
  • Technology
  • Real Estate
  • Sport
  • Travel
  • Lifestyle
  • Rankings
  • Explained
  • Opinion
Search
  • Gulf News
    • Saudi Arabia
    • UAE
    • Oman
    • Kuwait
    • Qatar
    • Bahrain
  • Business
  • Technology
  • Real Estate
  • Sport
  • Travel
  • Lifestyle
  • Rankings
  • Explained
  • Opinion
Have an existing account? Sign In
Follow US
  • Terms
  • About Us
  • Advertise with us
  • Contact Us
© 2023 Gulf Press. All Rights Reserved.

Home » Fraudulent Web3 Job Recruiters Enhance Their Cryptocurrency-Stealing Malware

Gulf News

Fraudulent Web3 Job Recruiters Enhance Their Cryptocurrency-Stealing Malware

News Room
Last updated: 2024/10/09 at 3:02 PM
News Room
Share
3 Min Read
SHARE

Fake Web3 job recruiters associated with North Korea are targeting job seekers online in a new cyber threat that involves tricking individuals into downloading malware that pretends to be a video call application. This malicious software is capable of stealing digital funds from various cryptocurrency wallets, such as MetaMask, BNB Chain, Exodus, Phantom, and more. The cyber risk team Unit 42 from Palo Alto Networks has identified these North Korean threat actors as likely being financially motivated to support the DPRK regime. The attackers reach out to software developers on job search platforms, posing as recruiters for online interviews, and convincing victims to install the malware under the guise of a video chat app.

The attackers operate by contacting tech industry job seekers and persuading them to download and execute the malware, which then works in the background to collect sensitive information and cryptocurrency. In a recent incident, a fake recruiter named “Onder Kayabasi” targeted a full stack software engineer through LinkedIn, prompting the victim to run the malicious code in a virtual environment as a precaution. The malware, known as the BeaverTail downloader and InvisibleFerret backdoor, has undergone updates to steal browser passwords in macOS and cryptocurrency wallets on Windows and macOS. This sophisticated threat campaign aims to infect, steal information, and digital assets from individuals in the cryptocurrency, blockchain, cybersecurity, and online gambling sectors.

Unit 42 has been monitoring the activities of these threat actors since November 2023, initially identifying the “Contagious Interview campaign” that has since evolved with new iterations. The attackers utilize the Qt cross-platform framework to develop malware that can simultaneously target both Windows and macOS systems. The newly updated BeaverTail malware targets 13 different cryptocurrency wallet browser extensions, expanding from the previously recorded 9 wallets. These extensions include popular wallets like MetaMask, BNB Chain, Exodus, TronLink, and more, demonstrating the attackers’ financial interests in stealing crypto funds. Additionally, the attackers employ the InvisibleFerret backdoor to maintain control of infected devices and exfiltrate sensitive data, posing a significant risk to both individuals and organizations targeted in this campaign.

The potential infiltration of companies that employ the targeted job seekers is a major concern highlighted in Unit 42’s report, emphasizing the need for awareness and protection against these advanced social engineering tactics. Individuals and organizations are advised to be cautious of unsolicited contact from recruiters, especially if it involves downloading unfamiliar applications or running suspicious code. By implementing security measures and staying informed about evolving cyber threats, individuals can safeguard themselves and their organizations from falling victim to such malicious activities. Unit 42’s report offers practical guidelines for protection and mitigation against these sophisticated attack campaigns, underscoring the importance of staying vigilant in the ever-changing landscape of cybersecurity.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
I have read and agree to the terms & conditions
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share this Article
Facebook Twitter Copy Link Print
Previous Article Minister of State says goodbye to Sri Lankan diplomat
Next Article Crude Oil experiences another sharp drop with losses exceeding 7% in just two days Crude Oil experiences another sharp drop with losses exceeding 7% in just two days
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

235.3k Followers Like
69.1k Followers Follow
56.4k Followers Follow
136k Subscribers Subscribe
- Advertisement -
Ad imageAd image

Latest News

Abdullah bin Hamad Al-Attiyah 50 Years of Energy Leadership
Qatar June 2, 2026
Two Emergency Spinal Surgeries Succeed at Rustaq Hospital
Oman June 2, 2026
Electricity Services Committee Approves Energy Storage Sites in Al-Mutlaa and Jabir Al-Ahmad
Kuwait June 2, 2026
Foreign Minister Strengthens Friendship and Cooperation Ties with the Philippines
Bahrain June 2, 2026

You Might also Like

Qatar

Abdullah bin Hamad Al-Attiyah 50 Years of Energy Leadership

June 2, 2026
Oman

Two Emergency Spinal Surgeries Succeed at Rustaq Hospital

June 2, 2026
Kuwait

Electricity Services Committee Approves Energy Storage Sites in Al-Mutlaa and Jabir Al-Ahmad

June 2, 2026
Bahrain

Foreign Minister Strengthens Friendship and Cooperation Ties with the Philippines

June 2, 2026
UAE

Post-Eid Return Shock: 8 Health Issues Dragging Employee Productivity

June 2, 2026
Saudi Arabia

Hajj Message: From Administration to Coexistence and Religious Moderation

June 2, 2026
UAE

Health Ministry Reveals 6 Ebola Symptoms Like Flu and 4 Travel Precautions

June 2, 2026
Saudi Arabia

Harvard Graduation Sees 70 Saudi Graduates From Elite Institutions

June 2, 2026
//

GulfPress is a modern Gulf media platform delivering trusted news, business insights, technology updates, real estate trends, travel stories, explainers, and rankings from across the GCC and the Middle East.

Quick Link

  • About Us
  • Editorial Policy
  • Corrections Policy
  • Advertise with us
  • Contact Us
  • Privacy Policy
  • Terms of use

How Topics

  • Gulf News
  • Business
  • Lifestyle

Sign Up for Our Newsletter

Subscribe to our newsletter to get our latest news instantly!

I have read and agree to the terms & conditions
Gulf PressGulf Press
Follow US

© 2023 Gulf Press. All Rights Reserved.

Join Us!

Subscribe to our newsletter and never miss our latest news, podcasts etc..

I have read and agree to the terms & conditions
Zero spam, Unsubscribe at any time.

Removed from reading list

Undo
Welcome Back!

Sign in to your account

Lost your password?