In brief – Singapore’s police force and cyber security agency put losses from a scam using fake job offers and compromised software systems at $11.8 million. – They describe a case in which a victim was approached by a bogus recruiter for a crypto firm and steered into a coding…
sessment run on a company laptop. – The malware harvested a session token, which was used to bypass multi-factor authentication and open the victim’s Bitbucket account. Scammers posing as recruiters for cryptocurrency companies have taken $11.8 million (S$15.1 million), using fake job offers to compromise their targets’ employers, according to a joint advisory from the Singapore Police Force and the Cyber Security Agency of Singapore
Setting out how the scam works in a statement on Friday, reported by The Straits Times and Channel NewsAsia, the agencies said a victim was approached on LinkedIn by someone posing as a recruiter for a crypto company, then moved to email, where the sender used a spoofed domain closely resembling a real firm’s. Several interviews followed on Google Meet. The interviewer kept their camera off throughout.
The victim was then sent to a spoofed website to complete a technical coding assessment, and did so on a company-issued device, downloading malicious software in the process without realizing it. The malware captured a session token, the string a service issues to keep a user logged in. Because the token represents an already-authenticated session, presenting it bypassed multi-factor authentication and opened the victim’s Bitbucket account, where the company stores and manages its source code.