According to a report from cybersecurity firms SentinelOne and Validin, and corroborated by 25 experts and victims, this scam is now ubiquitous. The scheme, which has been dubbed "Contagious Interview," involves hackers reaching out to potential targets on platforms like LinkedIn and Telegram with seemingly legitimate job offers from well-known crypto companies.
The scam begins with a recruiter pitching a job and then directs the applicant to an obscure website to complete a "skills test." At this point, applicants are asked to record a video, often requiring them to download malicious code. One victim, a product manager for a U.S. cryptocurrency firm, realized he had been duped only after he saw that $1,000 worth of crypto was missing from his digital wallet after following the instructions.
These elaborate schemes have become more convincing over time. Carlos Yanez, a business development executive at Global Ledger, noted that the quality of these impersonations has improved significantly. "It's scary how far they’ve come," he said.
While it is difficult to determine the exact amount stolen through this specific tactic, North Korean hackers are believed to have stolen at least $1.34 billion in cryptocurrency last year alone. The U.S. and United Nations monitors have alleged that these thefts are used to fund North Korea's sanctioned weapons program.
Companies like Robinhood and Kraken are aware of the impersonation campaigns and are taking steps to combat them, but they admit it's a difficult problem to police. Nick Percoco, Kraken’s chief security officer, said the company receives frequent reports from people who were targeted. "Every day there's something going on," he stated.
