A joint circular between the Singapore Police and the Singapore Cyber Security Authority states that a type of fraud that impersonates recruitment to encryption companies has resulted in losses of approximately $11.8 million. Such attacks do not directly target individual wallets, but rather use the recruitment process to enter the enterprise system and further access to funds and internal authority.

The attack starts with LinkedIn contact.

The circular indicated that the victim had first been contacted on LinkedIn by a recruit claiming to be from an encryption company and then referred to e-mail communication. The other used a pseudonym that was highly similar to the real company and arranged multiple rounds of interviews through Google Meet, where the interviewer did not open a camera at all.

Upon gaining confidence, the assailant leads the victim to a fake website, requiring completion of technical coding tests. If the victim downloads and runs the relevant documents on the company's distribution equipment, the malicious procedure is implanted into the system.

Steal tokens and overload factor authentication

Singaporean institutions have disclosed that malicious proceedings may steal a message. The message tokens represent the user who has completed the log-in verification, so that the assailant can enter the victim ' s account directly without repeating the multiple-factor authentication information.

In the cases disclosed, the attackers opened the victim ' s Bitbucket account. Bitbucket is often used in business code storage and management. After entering the account, the attackers continued to modify the employer ' s software system and further access to internal servers.

  • Some $11.8 million of declared losses
  • Impacts include code warehouse and internal servers
  • Common entry points are false recruitment and forgery technology tests.

Target has shifted to corporate finance and authority.

It was reported that the attackers subsequently collected additional internal documentation and used that information to bypass transaction limits and clearance checks for the eventual transfer of funds. The joint communication did not disclose the names of the companies affected, nor did it state where the funds went or clearly attributed them to the particular attack organization.

This technique is similar to the “Contagious Interview” operation, which has long been tracked by security researchers. Activities usually target Web3 developers and use false recruitment to induce them to operate malicious codes. The researchers also mentioned that some of the attackers would impersonate companies such as Coinbase and Uniswap for recruitment, thereby entering the enterprise cloud system and not simply stealing personal assets.

Officially recommended I.D.

The Singapore Police and the Cyber Security Service recommend that individuals verify the identity of the recruiter through official channels, be vigilant about the interviewer who refuses to open the camera and do not operate code or procedure of unknown origin.

For enterprises, the focus is on the protection of API keys and internal vouchers, the enhancement of multifactor certification, and the monitoring of the entry and unusual network activities of unfamiliar equipment. Once the system is suspected of having been breached, the affected equipment should be isolated, active sessions cancelled, vouchers replaced and access logs checked as soon as possible.