Connect with us

Hi, what are you looking for?

Top Stories

North Korean Hackers Target Crypto Developers in Job Scam Exposed by Fireblocks

Fireblocks reveals North Korean hackers are running a fake crypto job scheme to infect developers with malware.

On January 22, 2026, Fireblocks unveiled a disturbing campaign orchestrated by North Korean hackers, specifically linked to the notorious Lazarus Group. This operation, named “Operation Contagious Interview,” aimed to lure cryptocurrency developers into a trap using a fake job recruitment scam.

The hackers masqueraded as Fireblocks recruiters on LinkedIn, meticulously crafting profiles that appeared legitimate. These profiles included plausible work histories, professional images, and networks associated with the blockchain and tech sectors. Once engaged, targeted developers received well-designed PDFs detailing a fictitious project called the “Fireblocks Poker Platform.”

To enhance credibility, the scammers created detailed Figma boards and avoided common errors seen in phishing attempts. The attack was notably sophisticated; it referenced recent company updates, such as Fireblocks” acquisition of Dynamic, which had been announced shortly before the scam”s emergence.

As part of the scheme, potential victims underwent video interviews via Google Meet, during which interviewers asked standard questions about their experience and salary expectations. After discussing their qualifications, candidates were abruptly told the interviews were over, just before being assigned a “code review task.”

The malicious code was executed when victims followed typical developer procedures by cloning a GitHub repository and running the command “npm install.” This critical step enabled malware to infiltrate their systems.

Adding to the complexity, the attackers employed a technique known as “EtherHiding,” which utilized blockchain smart contracts to maintain their command-and-control operations, making detection and removal significantly more challenging.

In identifying the threat actor, Fireblocks connected the operation to APT 38, the same group responsible for previous scams. The investigation revealed that this operation closely mirrored earlier attempts to impersonate Multibank Group using a similar poker platform scam.

The objective of these attacks was clear: to gain financial access through stolen credentials, private keys, seed phrases, and entry to development environments. By executing malicious code on company devices, hackers could establish footholds within organizational systems, making developers prime targets.

Fireblocks identified twelve false identities utilized throughout the campaign, including names like “Agnes Gonzales” and “Roman Creed.” Red flags included the use of personal email addresses for corporate recruitment, links to Calendly on personal domains, AI-generated profile content, and LinkedIn accounts with minimal activity that suddenly became very active.

The operation came to light when multiple job seekers reached out directly to Fireblocks employees, inquiring about the so-called “Fireblocks Poker Platform.” These inquiries prompted an investigation by the security team, which confirmed the impersonation and initiated reporting to LinkedIn for the takedown of the fraudulent profiles. Malicious repositories were also removed in coordination with intelligence partners and law enforcement.

For those navigating the job market in the cryptocurrency sector, Fireblocks advises verifying all recruiter communications against official company careers pages. Legitimate recruiters affiliated with Fireblocks utilize verified LinkedIn profiles that are authenticated with company email addresses. If an interviewer requests that you clone a repository and execute installation commands, it warrants a careful reconsideration, even if everything else seems professional.

You May Also Like

Markets

Bitcoin"s value against gold has reached a critical support level; will it bounce back?

Top Stories

BitRss provides real-time updates and curated content for the crypto community around the clock

Altcoins

Ripple, XRP, and the XRP Ledger are distinct entities crucial for cross-border payments.

Markets

AVAX is currently trading between $21.40 support and $23.50 resistance levels, with potential for short-term recovery.

Markets

Dogecoin"s open interest has fallen to its lowest in six months, signaling potential price volatility ahead.

Business

Ripple"s recent achievements spark discussions on an IPO, though the company denies any immediate plans.

Bitcoin

Bitcoin"s price has dropped below the critical $100,000 level, raising concerns among investors.

Altcoins

LivLive offers a 200% bonus in its presale, making it a standout option for investors seeking affordable crypto.

Top Stories

A counterfeit Hyperliquid app has been identified, raising concerns over user scams.

Regulation

Finland will adopt the OECD"s Crypto-Asset Reporting Framework to enhance crypto transaction transparency by 2026.

Regulation

Nvidia"s stock drops sharply after the US bans AI chip sales to China, impacting growth plans.

Altcoins

XRP is poised to play a crucial role in a $30 trillion market for tokenized assets, reshaping finance.

Copyright © 2024 COINNEWSBYTE.COM. All rights reserved. This website provides educational content, emphasizing that investing involves risks. Ensure you conduct thorough research before investing and be ready for any potential losses. For those over 18 and interested in gambling: Online gambling laws differ across countries; adhere to your local regulations. By using this site, you agree to our terms, including the presence of affiliate links that do not impact our evaluations. Cryptocurrency offers on this site are not in line with UK financial promotion regulations and are not aimed at UK consumers.