Fireblocks has disclosed details of a highly coordinated cyber campaign in which North Korean threat actors impersonated the company’s recruiters to target cryptoFireblocks has disclosed details of a highly coordinated cyber campaign in which North Korean threat actors impersonated the company’s recruiters to target crypto

Fireblocks Exposes Sophisticated Lazarus-Linked Hiring Scam

2026/01/23 15:04
4 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Fireblocks has disclosed details of a highly coordinated cyber campaign in which North Korean threat actors impersonated the company’s recruiters to target crypto developers with malware. The investigation, published on January 22, 2026, revealed that attackers linked to the Lazarus Group leveraged fake recruitment processes to compromise victims’ systems and steal sensitive digital asset credentials.

The operation, internally labeled Operation Contagious Interview by Fireblocks’ security team, demonstrated a high level of sophistication. Attackers posed as legitimate Fireblocks recruiters on LinkedIn and used realistic hiring workflows to establish credibility before delivering malicious payloads disguised as routine coding tasks.

Impersonation Tactics and Social Engineering

According to the findings, the attackers created multiple convincing LinkedIn profiles that appeared to belong to Fireblocks executives, recruiters, and hiring managers. These profiles included professional photographs, detailed employment histories, and network connections aligned with blockchain and technical roles. Unlike many phishing attempts, the campaign avoided obvious warning signs such as spelling mistakes or poor formatting.

Once developers engaged with these profiles, they were sent professionally designed PDF documents outlining a fictitious initiative referred to as the Fireblocks Poker Platform. To further reinforce authenticity, the attackers built detailed design mockups using tools such as Figma. The materials closely mirrored Fireblocks’ real branding and referenced the company’s recent acquisition of Dynamic, which had been announced only weeks earlier. This level of accuracy indicated that the attackers were actively monitoring Fireblocks’ public announcements.

Fake Interviews and Malware Delivery

The scam extended beyond written communication into live interaction. Victims were invited to video interviews conducted over Google Meet, where the impostors followed standard hiring practices by asking about work experience and compensation expectations. After establishing rapport, the interviewers assigned what was presented as a code review or technical assessment and abruptly ended the call, citing scheduling constraints.

The malicious stage of the attack occurred when candidates followed standard developer workflows. Victims were instructed to clone a GitHub repository and run npm install, a common setup step. Executing this command triggered hidden malicious code, granting attackers access to the victim’s system. The malware infrastructure also employed a technique known as EtherHiding, which uses blockchain smart contracts to host command-and-control instructions, making the operation more resilient to takedowns.

Attribution to the Lazarus Group

Fireblocks’ security research team attributed the campaign to APT 38, a subgroup of the Lazarus Group known for financially motivated cyber operations. The investigation identified similarities with earlier attacks, including a previous recruitment scam that impersonated Multibank Group and used a comparable fake poker platform as bait.

The primary objective of the operation was financial theft. By compromising developers’ machines, the attackers sought to steal credentials, private keys, seed phrases, and access to development environments. Because developers often have elevated access to production systems and sensitive repositories, successful infections could provide attackers with entry points into entire organizations.

Indicators and Campaign Disruption

Fireblocks identified at least twelve fake personas used during the campaign. Indicators of compromise included the use of personal email addresses instead of corporate domains, Calendly links hosted on non-corporate sites, AI-generated profile descriptions, and LinkedIn accounts with little historical activity that suddenly became active.

The campaign began to unravel when several job seekers contacted Fireblocks employees directly to ask about the supposed poker platform project. These inquiries were escalated internally, allowing the security team to confirm the impersonation. Fireblocks then worked with LinkedIn to report and remove fraudulent profiles and coordinated the takedown of malicious repositories.

Guidance for the Crypto Community

Fireblocks has stated that it coordinated with intelligence partners and law enforcement to reduce the risk of follow-on attacks. The company, which reports securing more than $10 trillion in digital asset transfers across hundreds of millions of wallets, emphasized the importance of vigilance during recruitment processes.

Job seekers in the crypto sector are advised to verify recruiter outreach against official company career pages and ensure that communications originate from verified corporate email addresses. Fireblocks also noted that being asked to clone repositories and run installation commands as part of an interview process should be treated with caution, even when the overall interaction appears legitimate.

The post Fireblocks Exposes Sophisticated Lazarus-Linked Hiring Scam appeared first on CoinTrust.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

LgMining uses advanced mining equipment and intelligent technology: leading the new energy intelligent computing power revolution, the world’s most efficient cloud mining platform

LgMining uses advanced mining equipment and intelligent technology: leading the new energy intelligent computing power revolution, the world’s most efficient cloud mining platform

The post LgMining uses advanced mining equipment and intelligent technology: leading the new energy intelligent computing power revolution, the world’s most efficient cloud mining platform appeared on BitcoinEthereumNews.com. In the rapidly evolving world of cryptocurrency, individuals are always on the lookout for simple, efficient, and profitable ways to dive into the digital currency space. Cloud mining has gained tremendous popularity for its ease of use and accessibility, allowing beginners and seasoned investors alike to mine cryptocurrencies without investing in expensive hardware or managing complex setups. Among the myriad of options available, LgMining stands out as a premier platform for free cloud mining. Whether you’re aiming to earn Bitcoin, Ethereum, or other top cryptocurrencies, LgMining offers an incredibly attractive opportunity to earn passive income effortlessly. The Power of Cloud Mining: No Hardware, No Hassle Cloud mining offers a streamlined approach to cryptocurrency mining. Unlike traditional methods that require high-powered mining rigs, costly equipment, and technical expertise, cloud mining allows you to rent computational power from remote data centers. This eliminates the need for complex setups and maintenance while enabling users to mine digital currencies efficiently. Cloud mining is ideal for those who want to generate income from cryptocurrency mining without the associated high costs, risks, or energy consumption. LgMining: Leading the Cloud Mining Revolution LgMining is revolutionizing the world of cloud mining with its user-friendly platform, powerful mining infrastructure, and innovative approach to sustainability. The platform provides access to top-tier mining hardware and utilizes renewable energy sources like wind and solar power to maximize efficiency. This not only reduces costs but also ensures that users benefit from eco-friendly mining practices. With more than 5.8 million active users globally, LgMining has built a reputation for reliability, security, and transparency. By removing the barriers to entry that traditional mining methods present, LgMining makes it possible for anyone—whether a novice or an experienced crypto enthusiast—to profit from cryptocurrency mining without dealing with the complexities of setting up mining rigs. Free Cloud Mining…
Share
BitcoinEthereumNews2025/09/18 19:30
Tesla (TSLA) Stock Climbs as Its Biggest Battery Maker Crushes Estimates

Tesla (TSLA) Stock Climbs as Its Biggest Battery Maker Crushes Estimates

TLDR Tesla (TSLA) stock rose 1.2% to $403.25 on Tuesday after battery supplier CATL beat Q4 earnings expectations. CATL reported net income of $3.3B vs. the $2.
Share
Coincentral2026/03/10 21:24
“Bitcoin Is Going to Die”- Hollywood Fame Terrence Howard Warns BTC Investors

“Bitcoin Is Going to Die”- Hollywood Fame Terrence Howard Warns BTC Investors

The post “Bitcoin Is Going to Die”- Hollywood Fame Terrence Howard Warns BTC Investors appeared on BitcoinEthereumNews.com. Oscar-nominated Hollywood actor Terrence
Share
BitcoinEthereumNews2026/03/10 20:54