Executive Summary
In July 2026, a sophisticated social engineering campaign targeted cryptocurrency professionals using fake recruiter personas on LinkedIn and Calendly-based interview lures. Victims were directed to a malicious technical assessment hosted on Google Apps Script, which functioned as a triage platform to deliver platform-specific malware. For Windows users, the campaign utilized signed Microsoft ClickOnce applications to bypass traditional security warnings and deploy a triple-payload bundle.
The attack chain involves a complex multi-stage loading process featuring a custom 'Vortex' authenticated shellcode container and modified Donut loaders. The final payloads include NeedleStealer, a high-capability Rust-based stealer, and a custom Go remote access trojan (RAT) with hidden VNC (hVNC) capabilities. These tools are designed for total credential harvesting, targeting not only browser data and wallets but also developer-specific secrets like AWS keys, GitHub tokens, and SSH material.
This activity shows significant overlap with established DPRK-nexus 'Contagious Interview' patterns and shared MaaS/traffer infrastructure. The impact is severe, involving immediate private key compromise and automated wallet draining. Organizations in the cryptocurrency and decentralized finance sectors should remain highly vigilant regarding unsolicited recruitment outreach that requires technical assessments or software installations.
