Fake Crypto Job Offers Yield $11.8 Million in Sophisticated Corporate Cyber Scam
Singapore agencies warn of malicious coding tests used to bypass multi-factor authentication and raid corporate servers.
Cybercriminals posing as cryptocurrency recruiters stole $11.8 million (S$15.1 million) by exploiting company laptops through fake job interviews, according to a joint advisory released Friday by the Singapore Police Force and the Cyber Security Agency of Singapore.
The operation began on LinkedIn before shifting to spoofed email addresses mimicking legitimate firms, authorities reported in statements covered by The Straits Times and Channel NewsAsia. Attackers conducted multiple Google Meet interviews with their cameras switched off before directing targets to complete a technical coding assessment on spoofed websites using their employer-issued devices.
Once installed, the underlying malware intercepted active session tokens—unique identifiers that keep users logged into web services. By presenting the captured tokens, attackers bypassed multi-factor authentication protections and gained direct entry into victims’ Bitbucket accounts, where companies host and manage proprietary source code.
Infiltrating the repository enabled attackers to modify company software and breach internal servers. The joint advisory detailed how intruders extracted internal credentials from those servers, allowing them to override transaction limits and bypass approval checks to siphon funds.
While the Singapore advisory refrained from naming affected corporate targets or specific threat actors, cybersecurity researchers have documented identical tactics in an ongoing campaign known as Contagious Interview. That operation has seen attackers upload more than 300 malicious packages to the npm registry, with researchers attributing such activity to North Korean state-linked threat groups.
Similar corporate cloud intrusions targeting funds have been linked to a group designated TraderTraitor, alongside imposter campaigns impersonating major crypto entities such as Coinbase and Uniswap. The strategy extends beyond state-sponsored groups; Russian-speaking cybercrime group Crazy Evil previously established a fake Web3 entity called ChainSeeker.io to lure blockchain job applicants into installing wallet-draining malware.
To mitigate risks, Singapore authorities advised organizations to secure API keys, monitor network traffic for unfamiliar devices, and immediately revoke active sessions, isolate affected systems, and review access logs if a breach is suspected.









