The Singapore Police, together with the Singapore Cyber Security Authority, reported on August 14, that an attack disguised as a recruitment process for the encryption industry had resulted in a loss of $11.8 million for a business. The attackers first contacted the injured staff through LinkedIn, then used the technical test to place the malware program, then entered the company code warehouse and internal system and bypassed encrypted transfer controls.

This incident shows that attacks against the encryption industry are no longer limited to wallets or trading accounts and that developers ' equipment, code warehouses and automated deployment systems are becoming new breakthroughs.

The attack starts with a fake recruitment.

According to the circular, the victim was initially contacted on LinkedIn by a conspirator impersonating a recruiter for the encrypted company. The parties then moved to e-mail communication, using a counterfeit address that was highly similar to the real company domain name.

Victims also participated in several rounds of Google Meet interviews. As the process moved forward, the counterpart directed it to a counterfeit site and requested that technical coding tests be completed on the company distribution equipment. The malicious software was downloaded into the equipment in the process and the victim was not aware of it.

The session token was stolen, the MFA was bypassed

The Singapore Police and the Cyber Security Service indicated that the malicious procedure was installed and the victim ' s message signs were stolen. Using this token, the attackers bypassed multiple identifications and entered the victim ' s Bitbucket account.

As the account was linked to the employer ' s code warehouse, the attackers were subsequently able to revise the company ' s automated software deployment instructions and further remote access to the enterprise server and internal infrastructure.

The certificates obtained during the invasion were subsequently used to circumvent the transaction limits and clearance checks set by the company for encrypted transfers. Ultimately, the attackers initiated several encrypted transactions, resulting in losses totalling $11.8 million.

  • Initial Exposure Platform: LinkedIn
  • Follow-up communication tool: e-mail, Google Meet
  • Critical affected systems: Bitbucket, internal server, transfer approval process

Developer environment continues to be targeted

Such attacks in the name of recruitment have been repeated in the encryption industry. The attackers usually first contact the developers or technical personnel and then induce them to operate codes, install software or execute orders to control the work equipment.

The report mentions that the TrapDoor malware disclosed in May used to target encryption and AI developers through malicious packages in npm, PyPI and Rust ecology. According to researchers, such attacks not only steal wallet information but also collect GitHub tokens, API keys, cloud vouchers and SSH access rights.

In April of this year, another round of Obsidian-related attacks also reached out to encryption and financial practitioners via LinkedIn and Telegram to induce the target to install poison plugs. The researchers noted at the time that the attackers were increasingly coming from the “people” chain, rather than attacking the bottom of the wallet.

Response advice from Singapore authorities

The Singapore authorities have recommended that enterprises enhance the protection of API keys, internal vouchers, multiple identification, code warehouses and automated deployment processes, as the path of attack may rapidly extend to the production system following the loss of single-staff equipment.

In the case of businesses suspected of having been invaded, the authorities recommended the immediate isolation of the affected equipment or systems, the cancellation of active sessions, the replacement of vouchers, and checking whether access logs, code warehouses, internal servers and approval processes had been altered. At the same time, internal security teams or external security services should be contacted as soon as possible to confirm exposure and unauthorized operations.