Fireblocks has disclosed details of a highly coordinated cyber campaign in which North Korean threat actors impersonated the company’s recruiters to target cryptoFireblocks has disclosed details of a highly coordinated cyber campaign in which North Korean threat actors impersonated the company’s recruiters to target crypto

Fireblocks Exposes Sophisticated Lazarus-Linked Hiring Scam

2026/01/23 15:04
4 min read

Fireblocks has disclosed details of a highly coordinated cyber campaign in which North Korean threat actors impersonated the company’s recruiters to target crypto developers with malware. The investigation, published on January 22, 2026, revealed that attackers linked to the Lazarus Group leveraged fake recruitment processes to compromise victims’ systems and steal sensitive digital asset credentials.

The operation, internally labeled Operation Contagious Interview by Fireblocks’ security team, demonstrated a high level of sophistication. Attackers posed as legitimate Fireblocks recruiters on LinkedIn and used realistic hiring workflows to establish credibility before delivering malicious payloads disguised as routine coding tasks.

Impersonation Tactics and Social Engineering

According to the findings, the attackers created multiple convincing LinkedIn profiles that appeared to belong to Fireblocks executives, recruiters, and hiring managers. These profiles included professional photographs, detailed employment histories, and network connections aligned with blockchain and technical roles. Unlike many phishing attempts, the campaign avoided obvious warning signs such as spelling mistakes or poor formatting.

Once developers engaged with these profiles, they were sent professionally designed PDF documents outlining a fictitious initiative referred to as the Fireblocks Poker Platform. To further reinforce authenticity, the attackers built detailed design mockups using tools such as Figma. The materials closely mirrored Fireblocks’ real branding and referenced the company’s recent acquisition of Dynamic, which had been announced only weeks earlier. This level of accuracy indicated that the attackers were actively monitoring Fireblocks’ public announcements.

Fake Interviews and Malware Delivery

The scam extended beyond written communication into live interaction. Victims were invited to video interviews conducted over Google Meet, where the impostors followed standard hiring practices by asking about work experience and compensation expectations. After establishing rapport, the interviewers assigned what was presented as a code review or technical assessment and abruptly ended the call, citing scheduling constraints.

The malicious stage of the attack occurred when candidates followed standard developer workflows. Victims were instructed to clone a GitHub repository and run npm install, a common setup step. Executing this command triggered hidden malicious code, granting attackers access to the victim’s system. The malware infrastructure also employed a technique known as EtherHiding, which uses blockchain smart contracts to host command-and-control instructions, making the operation more resilient to takedowns.

Attribution to the Lazarus Group

Fireblocks’ security research team attributed the campaign to APT 38, a subgroup of the Lazarus Group known for financially motivated cyber operations. The investigation identified similarities with earlier attacks, including a previous recruitment scam that impersonated Multibank Group and used a comparable fake poker platform as bait.

The primary objective of the operation was financial theft. By compromising developers’ machines, the attackers sought to steal credentials, private keys, seed phrases, and access to development environments. Because developers often have elevated access to production systems and sensitive repositories, successful infections could provide attackers with entry points into entire organizations.

Indicators and Campaign Disruption

Fireblocks identified at least twelve fake personas used during the campaign. Indicators of compromise included the use of personal email addresses instead of corporate domains, Calendly links hosted on non-corporate sites, AI-generated profile descriptions, and LinkedIn accounts with little historical activity that suddenly became active.

The campaign began to unravel when several job seekers contacted Fireblocks employees directly to ask about the supposed poker platform project. These inquiries were escalated internally, allowing the security team to confirm the impersonation. Fireblocks then worked with LinkedIn to report and remove fraudulent profiles and coordinated the takedown of malicious repositories.

Guidance for the Crypto Community

Fireblocks has stated that it coordinated with intelligence partners and law enforcement to reduce the risk of follow-on attacks. The company, which reports securing more than $10 trillion in digital asset transfers across hundreds of millions of wallets, emphasized the importance of vigilance during recruitment processes.

Job seekers in the crypto sector are advised to verify recruiter outreach against official company career pages and ensure that communications originate from verified corporate email addresses. Fireblocks also noted that being asked to clone repositories and run installation commands as part of an interview process should be treated with caution, even when the overall interaction appears legitimate.

The post Fireblocks Exposes Sophisticated Lazarus-Linked Hiring Scam appeared first on CoinTrust.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Avalanche and Hyperliquid Lead Crypto Rally Post-Fed Rate Cut

Avalanche and Hyperliquid Lead Crypto Rally Post-Fed Rate Cut

The post Avalanche and Hyperliquid Lead Crypto Rally Post-Fed Rate Cut appeared on BitcoinEthereumNews.com. In brief Crypto markets have posted broad gains following the Federal Reserve’s quarter-point rate cut. Hyperliquid’s USDH stablecoin has been “attracting liquidity across the board from many institutions,” according to an analyst. The momentum now hinges on project-specific catalysts, with altcoins more exposed to volatility than Bitcoin, experts told Decrypt. Avalanche (AVAX) and Hyperliquid (HYPE) led the altcoin rally on Thursday as digital assets responded positively to the Federal Reserve’s latest rate cut and project-specific developments. AVAX rocketed 10.1% to $32.59, while HYPE jumped 7.2% to $58.43 in the past 24 hours, according to CoinGecko data.  Other major altcoins followed suit, with Dogecoin (DOGE) advancing 5.4% to $0.27, Solana (SOL) climbing 4.5% to $244 and Cardano (ADA) rising 4.3% to $0.90. (ADA) rising 4.3% to $0.90.  Bitcoin (BTC) maintained its position above $117,000 with a modest 0.3% gain, while Ethereum (ETH) posted a 2.1% increase to $4,588. The rally follows the Fed’s widely anticipated quarter-point rate cut, which lowered the federal funds rate to a range of between 4.25% to 4.50%.  Bitcoin and other major digital assets largely traded flat in the immediate aftermath, as investors had already priced in the highly anticipated Fed call. “While the Fed’s rate cut buoyed broader risk sentiment, AVAX’s outperformance seems driven by Avalanche’s announcement of a $1 billion Digital Asset Treasury plan,” Min Jung, senior analyst at quantitative trading firm Presto, told Decrypt. The Avalanche Foundation is in advanced talks to raise $1 billion via a Nasdaq-listed firm backed by Hivemind and a Dragonfly-sponsored SPAC, with proceeds earmarked for discounted AVAX buybacks, according to the Financial Times. Bitwise also filed paperwork on Monday for an AVAX ETF, utilizing Coinbase to custody the digital assets, which adds to the token’s institutional adoption prospects. Jung noted the rally could “sustain in the near term…
Share
BitcoinEthereumNews2025/09/18 18:49
Pi Network Accelerates Real World Adoption as Picoin Transitions from Digital Asset to Everyday Payment

Pi Network Accelerates Real World Adoption as Picoin Transitions from Digital Asset to Everyday Payment

   The Pi Network ecosystem is once again demonstrating significant progress. While the community initially focused on mining ac
Share
Hokanews2026/02/12 20:27
Peter Schiff waarschuwt na koersval: Verkoop Bitcoin vóór de volgende halvering

Peter Schiff waarschuwt na koersval: Verkoop Bitcoin vóór de volgende halvering

De recente koersdaling van Bitcoin blijft de financiële wereld verdelen. Waar veel beleggers de terugval van bijna 50 procent sinds de piek in oktober 2025 zien
Share
Coinstats2026/02/12 20:16