[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fZp54PXXdNhfVLmclkjHB75D6CgAh_6QvXjZhzDVZHco":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":43},"22caeffa-1274-495a-9721-1ea7fe577157","fake-job-recruiters-drain-1071m-in-crypto-via-malware-campaign","0238dd87-6e76-4773-a9ba-b1565eaf2b16","Fake Job Recruiters Drain $10.71M in Crypto via Malware Campaign","The 'Contagious Interview' campaign exploited human trust and professional ambition by impersonating recruiters on social media platforms, luring victims into executing malware disguised as a legitimate job assessment. The root failure is a lack of security awareness among targeted professionals — web designers, engineers, and crypto specialists — who did not scrutinize the authenticity of recruitment contacts or the software they were asked to run. This is also a supply chain risk, as compromising individual contributors can cascade into broader organizational breaches. With 30,000 devices compromised and over $10 million stolen, the scale demonstrates that social engineering remains one of the most effective and underestimated attack vectors. Organizations must treat unsolicited recruitment activity as a potential threat vector and train employees accordingly.","**Immediate actions:**\n- Train all employees — especially engineers and crypto specialists — to verify recruiter identities through official company channels before engaging in any job assessment activities.\n- Establish a policy prohibiting the download or execution of software provided by external recruiters on corporate or personal devices used for work.\n\n**Long-term improvements:**\n- Implement application allowlisting to prevent unauthorized executables from running on endpoints, even if installed by the user.\n- Develop a formal third-party and recruitment vetting process that includes background verification of recruiter profiles and hiring organizations.\n- Conduct regular social engineering simulation exercises targeting recruitment-themed phishing scenarios.\n\n**Detection measures:**\n- Deploy endpoint detection and response (EDR) tools capable of identifying anomalous process execution consistent with malware staging or crypto-wallet access.\n- Monitor outbound network traffic for connections to known malicious infrastructure or unusual data exfiltration patterns from employee devices.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 14 – Security Awareness and Skills Training","CIS Control 10 – Malware Defenses","CIS Control 2 – Inventory and Control of Software Assets","NIST SP 800-53 AT-2 – Literacy Training and Awareness","NIST SP 800-53 SI-3 – Malicious Code Protection","NIST SP 800-53 SA-12 – Supply Chain Risk Management","NIST CSF ID.SC-2 – Supply Chain Risk Identification","MITRE ATT&CK T1566.003 – Phishing via Service (Social Media)","MITRE ATT&CK T1204 – User Execution","ISO\u002FIEC 27001 A.6.1 – Human Resource Security","GDPR Article 32 – Security of Processing (where EU data subjects are affected)","published","2026-09-21T20:21:07.192743+00:00","2026-09-21T20:21:06.891+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fcontagious-interview-campaign.html","contagious-interview-campaign-compromises-30-000-devices-steals-10-71m-in-crypto-c533ab","Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto",[31,37],{"id":32,"name":33,"slug":34,"description":35,"color":36},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":38,"name":39,"slug":40,"description":41,"color":42},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[44],{"id":45,"date":46,"edition":47,"title":48,"audio_url":49},"e5e752e4-9ee9-4b24-979e-435c24ee7ac2","2026-09-22","morning","ThreatNoir Morning Brief — September 22","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-09-22\u002Fthreatnoir-morning-brief-2026-09-22.mp3"]