Hunting for Web3 Specialists: Fake Interview App Steals Crypto Wallets
Cybercriminals have developed a new sophisticated scheme targeting Web3 professionals. Posing as recruiters, they offer jobs and then, using a fake video interview app, deploy malware that steals cryptocurrency wallet data. This campaign was identified during my own threat analysis.
Attack Mechanics: From Invitation to Theft
The attackers contact job seekers and propose discussing job details. The victim is then directed to a website that mimics the popular online meeting platform Relay. The resource looks convincing, promising speech transcription and collaborative note-taking features. In the next step, the victim is asked to install an interview program.
This is where the main trap lies. macOS users are instructed to drag a file into the terminal and press Enter, while Windows users are told to simply wait for the "Update" progress bar to fill. In reality, instead of installing the app, malicious code is executed. The user essentially infects their own system, disabling built-in security measures.
What the Virus Steals: Not Just Crypto Wallets
The primary goal is access to crypto assets. On macOS, the program displays a fake window requesting the system password, masquerading as an OS prompt. The entered password is linked to the user's credential database, enabling a breach of the device's keychain.
The malware is not limited to a single wallet. It steals passwords and cookies from browsers, password manager data, local Telegram files, and note contents. Targets include crypto wallet extensions such as MetaMask, Phantom, and Trust Wallet. The program also checks for the presence of Ledger Live and Trezor Suite.
The Windows version acts even more aggressively: it establishes persistence in the system for automatic startup after reboot and scans browser extension memory for data to unlock wallets.
My Recommendations for Protection
If you have only downloaded a suspicious file but not run it—simply delete it and empty the trash. If the program has already been executed, immediately disconnect the device from the network, but do not restart it, to preserve traces for investigation.
Then, from a clean device, change all passwords, revoke active sessions in the browser and Telegram. If you used wallet extensions, create new wallets on a clean device and transfer funds there. For an infected Windows computer, the most radical but reliable advice is to completely reinstall the operating system.
Expert Conclusion: This campaign is a prime example of social engineering targeting trusting job seekers. Never install third-party software at the request of "recruiters" and always verify the authenticity of job offers through official channels. Use hardware wallets for storing large amounts and never trust files from strangers.