A fake cryptocurrency job offer that infected a company-issued device has led to US$11.8 million in losses after attackers gained access to corporate systems and bypassed transaction controls, Singapore authorities have said.

Summary

  • A fake crypto job offer led to US$11.8 million in losses after malware infected a company device.
  • Attackers stole a session token, bypassed multi-factor authentication and accessed the company’s Bitbucket repository.
  • Stolen credentials were later used to bypass transaction limits and approval checks for crypto transfers.
  • Singapore authorities urged firms to secure credentials, code repositories and deployment systems.

The Singapore Police Force and Cyber Security Agency of Singapore said on Aug. 14 that the victim was first contacted on LinkedIn by a scammer posing as a recruiter from a cryptocurrency-related company, beginning an interview process that eventually gave the attackers access to the victim’s employer.

Communication moved from LinkedIn to email, where the supposed recruiter used a spoofed domain that closely resembled the legitimate company’s address. The victim also attended several interviews through Google Meet, although the person conducting the interviews kept their camera switched off during the calls.

As the recruitment process advanced, the victim was sent to a spoofed website and asked to complete a technical coding assessment on a company-issued device. Malicious software was downloaded during the assessment without the victim realizing the device had been compromised.

Fake crypto job assessment opened access to corporate systems

Once installed, the malware harvested the victim’s session token, SPF and CSA said. Attackers then used the stolen token to bypass multi-factor authentication and gain access to the victim’s Bitbucket account, which was connected to the employer’s code repository.

Bitbucket is a code repository hosting service used by software development teams to store, manage, and collaborate on source code. Access to an employee account can therefore expose more than the individual device when the account has permissions linked to company repositories or other development systems.

After entering the Bitbucket account, the attackers modified the company’s automated software deployment instructions, according to the two agencies. The intrusion then moved into the company’s internal infrastructure as the attackers remotely accessed its servers.

Credentials collected during the compromise allowed the attackers to bypass transaction limits and approval checks used to control cryptocurrency transfers. SPF and CSA said the attackers subsequently carried out crypto transactions that resulted in losses totaling US$11.8 million.

The use of a coding assessment as the malware delivery method resembles attacks previously documented across the cryptocurrency sector, where developers and other technical staff are approached with job offers before being asked to run code or install software.

In May, crypto.news reported on TrapDoor malware, which targeted cryptocurrency and artificial intelligence developers through malicious software packages. Developer security platform Socket found at least 34 malicious packages and 384 connected versions across npm, PyPI and Rust ecosystems.

According to Socket, the packages were designed to steal cryptocurrency wallet information alongside GitHub tokens, API keys, cloud credentials and SSH access. The campaign placed developer environments at the point of compromise, allowing attackers to target credentials that could provide access to systems outside a victim’s personal cryptocurrency accounts.

Crypto workers have faced repeated recruiter-based malware attacks

Recruitment-themed attacks have also relied on legitimate communication platforms to make initial contact appear credible before moving victims toward malicious software.

An April Obsidian malware campaign used LinkedIn and Telegram to approach cryptocurrency and finance professionals. Elastic Security Labs found that attackers relied on social engineering to convince targets to install malicious community plugins for the legitimate Obsidian note-taking application.

The malware, identified as PHANTOMPULSE, used three blockchain networks to receive commands and maintain persistence, according to Elastic Security Labs. Researchers recommended strict application-level plugin policies at financial companies to reduce the risk of legitimate productivity software being turned into an entry point for attackers.

During the same month, wallet provider Zerion confirmed a $100,000 breach tied to a long-running social engineering operation linked to North Korean attackers. The Zerion security breach involved attackers using artificial intelligence to impersonate trusted contacts before compromising hot-wallet credentials.

Security Alliance researchers connected that campaign to 164 malicious domains used in attempts to infiltrate cryptocurrency companies through services including Slack and LinkedIn. Zerion said the attackers had targeted the human side of its operations instead of directly breaking its underlying wallet technology.

SPF and CSA have not attributed the latest US$11.8 million loss to North Korea or any other hacking group.

Recruitment-based social engineering, however, has previously been used by North Korean threat actors against cryptocurrency businesses. Google Cloud and Wiz reported in 2025 that UNC4899, also known as TraderTraitor, had approached employees at crypto companies through LinkedIn and Telegram while posing as recruiters.

In incidents involving remote job approaches, employees were persuaded to execute malicious Docker containers on their workstations. The containers deployed downloaders and backdoors connected to attacker-controlled infrastructure, after which the group moved through internal networks, collected credentials, and searched for systems used to process cryptocurrency transactions.

Google said one incident allowed UNC4899 to disable multi-factor authentication on a privileged Google Cloud account and access wallet-related services. The group has been active since at least 2020 and has focused heavily on cryptocurrency and blockchain companies, according to the firm’s threat research.

Singapore authorities call for tighter repository and credential controls

Following the latest incident, SPF and CSA advised businesses and individuals, particularly those operating in technology and cryptocurrency, to verify the identities of recruiters and the companies they claim to represent before interacting with job-related files, websites or software.

Companies were also advised to protect application programming interface keys and internal credentials while strengthening multi-factor authentication. Securing code repositories and software deployment pipelines was specifically recommended because access to those systems can allow a compromise that starts on one employee device to reach company infrastructure.

The agencies also urged businesses to review how sensitive credentials are stored and accessed. In the latest case, credentials collected after the initial compromise were used to bypass transaction limits and approval checks, allowing the attackers to execute cryptocurrency transfers.

Developer access has remained a recurring target because software repositories and related tools can contain credentials or provide routes into cloud and production systems. The TrapDoor campaign discovered in May, for example, targeted GitHub tokens, SSH keys, and cloud credentials alongside cryptocurrency wallet data, giving attackers several types of access from a single infected developer environment.

Earlier recruiter scams have used similar steps with different malware delivery methods. A December 2024 fake interview campaign approached Web3 professionals through LinkedIn, Telegram, and freelance platforms with lucrative employment offers.

Targets were directed to a video interviewing service and asked ordinary industry questions before reaching a final video task. When victims encountered a supposed microphone or camera problem, they were shown troubleshooting instructions that required them to execute commands on their computers.

On-chain investigator Taylor Monahan said at the time that executing the commands could give attackers general access to the device, creating opportunities to steal sensitive information, monitor activity, or compromise cryptocurrency wallets.

Compromised devices should be isolated immediately

For businesses that suspect an employee device or internal system has already been breached, SPF and CSA advised isolating affected equipment or systems immediately.

Active sessions should be revoked, and credentials reset, while access logs should be examined for signs that attackers entered other accounts or company infrastructure. Authorities also advised businesses to check whether code repositories, internal servers, accounts or approval workflows had been changed during the compromise.

Internal cybersecurity teams or external security providers should be contacted without delay, according to the agencies. Investigators should determine which accounts and credentials were exposed and establish whether unauthorized changes were made after the initial intrusion.

For individuals, the agencies recommended treating unsolicited recruitment approaches with caution and independently verifying both the recruiter and the company involved. Extra scrutiny was advised when an interview process requires candidates to download files, run unfamiliar code, or use websites supplied by people they have not independently verified.

Companies were separately advised to review access to API keys and other internal credentials, strengthen multi-factor authentication controls, and secure development infrastructure, including repositories and automated deployment pipelines.



Source link


author

Leave a Reply

Your email address will not be published. Required fields are marked *