Crypto job scam in Singapore costs company $11.8 million

Singapore police warn of a wave of sophisticated attacks. Malware installed during a "job test" allowed attackers to bypass two-factor authentication, infiltrate the corporate code repository, and bypass transfer limits.

Source
Crypto job scam in Singapore costs company $11.8 million
Photo: ICE / ביטקוין סינגפור (צילום Shutterstock)

According to a report on the crypto.news website, the Singapore Police Force (SPF) and the Cyber Security Agency have uncovered a serious cyber incident in which a crypto company lost $11.8 million following a sophisticated social engineering attack. The attack began with a seemingly innocent approach to a company employee via LinkedIn and ended with full penetration into the organization's core infrastructure.

The modus operandi was based on impersonating a recruiter from a legitimate crypto company. Communication quickly moved to email sent from a spoofed domain, and the employee even underwent several interviews on Google Meet with an interviewer who kept their camera off. During the practical test phase, the employee was directed to a fake website and required to perform a coding task on the company computer, during which malware was installed without their knowledge.

The malware harvested the employee's session token, which allowed the attackers to bypass two-factor authentication and infiltrate the corporate Bitbucket account. From there, the attackers modified the automated software deployment instructions, penetrated internal servers, obtained elevated privileges, and bypassed transfer and approval limits—culminating in the execution of massive crypto transfers.

As noted in the report, law enforcement authorities did not attribute the attack to a specific group, but noted that this pattern is well-known. Attack groups, including those associated with North Korea, make extensive use of job postings and fictitious interviews to plant malware on the computers of developers in the crypto and Web3 industry.

Singaporean authorities are calling on organizations and developers to independently verify the identity of recruiters, tighten permissions in code repositories, and perform immediate isolation of devices suspected of being involved in a security incident.

Related News