A sophisticated campaign impersonating job recruiters has compromised at least 30,000 devices across more than 100 countries, resulting in the theft of over $10.71 million in cryptocurrency from more than 7,000 wallets, according to a joint cybersecurity advisory reported by The Hacker News.
The operation, dubbed the "Contagious Interview" campaign, weaponizes the trusted mechanics of the remote hiring process. Threat actors create fraudulent profiles on job platforms, targeting web designers, engineers, and cryptocurrency specialists for apparent freelance or contract work. During what appear to be legitimate remote interviews, victims are instructed to install software—such as browser extensions, video conferencing tools, or coding libraries—ostensibly required for a skills assessment.
Once this software is installed, it deploys malicious code, giving attackers persistent access to the compromised system. This access is then used to siphon digital assets and harvest sensitive credentials and intellectual property.
Researchers highlight the campaign's dual-purpose objective. While financial theft is a clear goal, the simultaneous harvesting of proprietary code and technical information points to an espionage component, blurring the lines between traditional cybercrime and intelligence gathering. This makes individual freelancers and independent contractors particularly high-value targets, as they often lack the security oversight and infrastructure of a large corporation.
Industry experts warn that the attack effectively weaponizes a routine step in modern professional life. The request to install new software during an interview is common and expected, helping the scheme bypass the natural skepticism of technically proficient users.
Cybersecurity advisories following the disclosure have urged developers and job seekers to adopt stricter operational security. Core recommendations include treating all unsolicited software installation requests as potentially hostile and independently verifying them through official company channels. Researchers also advise conducting interviews and technical assessments from a dedicated, clean device or virtual machine isolated from primary systems and crypto wallets to contain any potential breach.
The scale of the Contagious Interview campaign underscores a persistent vulnerability in the distributed workforce: the trust inherent in the hiring funnel itself. As the incident demonstrates, this trust is now being systematically exploited on a global scale.
根據 The Hacker News 報導的聯合網絡安全警告,一場冒充招聘人員的精密攻擊行動已入侵全球逾百個國家至少三萬台設備,導致超過七千個錢包中的逾一千零七十一萬美元加密貨幣被盜。
這項被稱為「傳染式面試」的攻擊行動,利用遠程招聘流程中的信任機制進行攻擊。威脅行為者在求職平台建立虛假檔案,鎖定網頁設計師、工程師及加密貨幣專家等自由職業或合約工作者。在看似合法的遠程面試中,受害者被要求安裝軟件——如瀏覽器擴充、視像會議工具或程式碼庫——聲稱用於技能評估。
軟件安裝後會部署惡意代碼,讓攻擊者持續存取受感染系統。這些權限隨後用於竊取數字資產及收集敏感憑證和知識產權。
研究人員指出該攻擊行動具有雙重目標。雖然金融盜竊是明確目標,但同時收集專有代碼及技術情報顯示其情報蒐集性質,模糊了傳統網絡犯罪與情報活動的界線。這使得個體自由職業者及獨立承包商成為特別高價值的目標,因其往往缺乏大型企業的安全監督機制及基礎設施。
業界專家警告,此攻擊手法有效地將現代專業生活中的常規步驟武器化。面試期間要求安裝新軟件是普遍且合理的做法,有助於該騙局繞過具備技術素養用戶的天然懷疑態度。
網絡安全公告在事件披露後,敦促開發者及求職者採取更嚴格的操作安全措施。核心建議包括將所有未經邀請的軟件安裝要求視為潛在惡意,並透過官方企業渠道獨立核實。研究人員亦建議,應使用與主要系統及加密貨幣錢包隔離的專用淨設備或虛擬機器進行面試及技術評估,以限制任何潛在入侵的影響範圍。
「傳染式面試」攻擊行動的規模凸顯了分散式工作模式中一個持續存在的漏洞:招聘流程本身內建的信任機制。正如此次事件所示,這種信任現正被有系統地在全球範圍內利用。
