Back to all lessons
Awareness Lessons
3 weeks ago

Fake Job Recruiters Drain $10.71M in Crypto via Malware Campaign

The 'Contagious Interview' campaign exploited human trust and professional ambition by impersonating recruiters on social media platforms, luring victims into executing malware disguised as a legitimate job assessment. The root failure is a lack of security awareness among targeted professionals — web designers, engineers, and crypto specialists — who did not scrutinize the authenticity of recruitment contacts or the software they were asked to run. This is also a supply chain risk, as compromising individual contributors can cascade into broader organizational breaches. With 30,000 devices compromised and over $10 million stolen, the scale demonstrates that social engineering remains one of the most effective and underestimated attack vectors. Organizations must treat unsolicited recruitment activity as a potential threat vector and train employees accordingly.

Tactical Insight

Immediate actions

  • Train all employees — especially engineers and crypto specialists — to verify recruiter identities through official company channels before engaging in any job assessment activities.
  • Establish a policy prohibiting the download or execution of software provided by external recruiters on corporate or personal devices used for work.

Long-term improvements

  • Implement application allowlisting to prevent unauthorized executables from running on endpoints, even if installed by the user.
  • Develop a formal third-party and recruitment vetting process that includes background verification of recruiter profiles and hiring organizations.
  • Conduct regular social engineering simulation exercises targeting recruitment-themed phishing scenarios.

Detection measures

  • Deploy endpoint detection and response (EDR) tools capable of identifying anomalous process execution consistent with malware staging or crypto-wallet access.
  • Monitor outbound network traffic for connections to known malicious infrastructure or unusual data exfiltration patterns from employee devices.