Published: · Region: Global · Category: cyber

Fake Web3 Job Lures Deliver Signed Malware, Exposing New Corporate Cyber Weakness

A July campaign posing as Web3 job interviews delivered a signed ClickOnce installer that quietly installed two information‑stealing programs and a remote‑access Trojan on Windows machines. The operation shows how attackers are weaponizing trust in code signatures and recruitment to slip past corporate defenses and siphon data.

The promise of a career break in the booming Web3 sector turned into a backdoor for data theft this summer, in a campaign that says as much about human vulnerability as it does about software flaws. By wrapping malicious code in the trappings of a legitimate, digitally signed installer, attackers found a way to turn job‑hunters’ hopes into an entry point for corporate espionage. Security researchers tracking the operation report that in July 2026, threat actors ran a phishing campaign built around fake Web3 “interviews.” Targets were approached with what appeared to be genuine opportunities in blockchain and crypto‑related firms, then sent a link to a Windows‑based application they were…

Pro features include

  • 60+ analytical tools across markets and intelligence
  • Custom alerts, watchlists, and AOI monitoring
  • Daily Pro brief at 6 PM ET — 12 hours before free tier
  • Conflict deep dives and premium research products