In a disturbing new trend, hackers are targeting job seekers in the cryptocurrency sector by employing a scheme that exploits microphone debugging to steal crypto assets. This alarming tactic was highlighted by Taylor Monahan, a developer at MetaMask, who warned the community about the rising threat.
Key Takeaways
-
Hackers are using fake job offers to lure candidates in the crypto industry.
-
The scheme involves a seemingly innocent video interview process.
-
Victims unknowingly install backdoors that allow hackers to access their devices.
-
The attack affects multiple operating systems, including macOS, Windows, and Linux.
The Scheme Unveiled
Job seekers in the cryptocurrency field have recently encountered a sophisticated cybercrime scheme aimed at stealing their digital assets. According to Taylor Monahan, the developer behind MetaMask, fraudulent job offers are proliferating on platforms like LinkedIn, freelance websites, Discord, and Telegram. These offers are disguised as recruitment efforts from well-known cryptocurrency exchanges such as Kraken, MEXC, and Gemini, as well as tech giants like Meta.
The fake recruiters are seeking candidates for technical roles, traders, and analysts, promising salaries ranging from $200,000 to $350,000. Initially, candidates are invited to participate in a text-based interview on a platform called Willo, where they are asked about cryptocurrency market trends and tasked with developing a business expansion strategy on a limited budget.
The Deceptive Process
As part of the interview process, candidates are required to submit a video response for a team collaboration exercise. During this process, a pop-up window requests access to the user's microphone and camera. However, the page subsequently displays a hardware error message, prompting users to update their drivers and restart their browser.
Following these instructions can lead to dire consequences. Monahan warns that regardless of the operating system—be it Mac, Windows, or Linux—executing these recommendations results in the installation of a backdoor, granting hackers access to the victim's device and enabling them to steal cryptocurrency funds.
Previous Incidents
This recent attack is reminiscent of a previous incident involving the Japanese cryptocurrency exchange DMM Bitcoin, which suffered a loss of $308 million due to a similar recruitment scam on LinkedIn. In that case, a hacker compromised an employee of a third-party company with access to the platform's assets. The FBI attributed that attack to state-sponsored North Korean hackers known as TraderTraitor.