Protecting Yourself from LinkedIn Scams: How to Stay Safe in the Web3 Era

2023-11-06 Coinmonks

https://medium.com/coinmonks/protecting-yourself-from-linkedin-scams-how-to-stay-safe-in-the-web3-era-25e6b0566fa6

Thumbnail for Protecting Yourself from LinkedIn Scams: How to Stay Safe in the Web3 Era

The source describes a LinkedIn job scam aimed at Web3 developers in which the attacker sent an archive of a repository rather than a simple executable. Analysis of the project found an obfuscated next.setup.js file that would run after dependency installation and project startup, then target browser profile paths, wallet extension storage, and a Solana id.json file. The authors noted possible follow-on download behavior through a p2.zip reference and compared the tradecraft to a Lazarus-linked campaign, while stressing that this sample was lower quality and collected data directly without a loader. The case is useful for tracking developer-focused social engineering and malicious repository delivery, but it should not be treated as firm Lazarus attribution beyond the source wording.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN officercia.mirror.xyz 2023-11-06 2023-11-06

Related Reports

« Back