ThreatCluster

Fake Job Interviews Used to Distribute Infostealer Malware Targeting Web3 Professionals

First seen 29 Jul 2026, 17:15 UTC GbhackersCybersecuritynews 70% similarity 65

Article Content

Browse articles
ThreatCluster

A cyber campaign has emerged targeting Web3 professionals with fake job interviews to deliver cross-platform infostealer malware. Attackers impersonate recruiters and direct victims to a malicious domain, relay.lc, where they are prompted to install a tool named 'Relay.' This malware is designed to harvest sensitive information, including crypto wallets and passwords. The attack is particularly aimed at Web3 developers who are actively seeking employment. The sophistication of the social engineering tactics used in this campaign raises concerns about the security of remote hiring processes. No specific numbers of affected individuals or organizations have been reported yet. The current status of the attack is ongoing, with warnings issued to potential victims.

Key Points: • Attackers impersonate recruiters to target Web3 professionals. • Malware delivered via a fake meeting tool called 'Relay.' • Campaign exploits the growing trend of remote job interviews.

ThreatCluster AI How this analysis works

Timeline

2026-07-29
Cyber campaign targeting Web3 professionals uncovered
Attackers use fake job interviews to deliver infostealer malware, compromising crypto wallets and credentials.
Gbhackers
2026-07-29
Fake recruiters identified in job scams
Attackers pose as recruiters and direct candidates to a malicious domain under the guise of normal hiring practices.
Cybersecuritynews

Community

Browse all →

Tracked Entities in This Story