Fake Job Interviews Used to Distribute Infostealer Malware Targeting Web3 Professionals
Article Content
- •Attackers impersonate recruiters to target Web3 professionals.
- •Malware delivered via a fake meeting tool called 'Relay.'
- •Campaign exploits the growing trend of remote job interviews.
A cyber campaign has emerged targeting Web3 professionals with fake job interviews to deliver cross-platform infostealer malware. Attackers impersonate recruiters and direct victims to a malicious domain, relay.lc, where they are prompted to install a tool named 'Relay.' This malware is designed to harvest sensitive information, including crypto wallets and passwords. The attack is particularly aimed at Web3 developers who are actively seeking employment. The sophistication of the social engineering tactics used in this campaign raises concerns about the security of remote hiring processes. No specific numbers of affected individuals or organizations have been reported yet. The current status of the attack is ongoing, with warnings issued to potential victims.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…