- Hackproofing.com
- Posts
- 🚨 Fake Linkedin Jobs - Malicious "Fix" Links Putting Your Security At Risk
🚨 Fake Linkedin Jobs - Malicious "Fix" Links Putting Your Security At Risk
Social Engineering From Linkedin Job Offers?
VaultCraft closes the year with $100M+ TVL
VaultCraft levels up: Launches V2 and lands $100M+ Bitcoin partnership
VaultCraft partners with Safe & Matrixport
OKX Web3 rolls out Safe Smart vault with $250K rewards
The Issue: Video Permissions Gone Wrong
Tay (@tayvano_) shared her experience with a frustrating issue: granting permissions for video functionality showed a green light indicating activation, but the video feature remained non-functional. A seemingly helpful "How to fix" link was provided, directing her to what appeared to be a legitimate solution.
🚨 Heads up all—some dudes have a slick, new way of dropping some nasty malware.
Feels infostealer-y on the surface but...its not.đź«
It'll really, deeply rekt you.
Pls share this w/ your friends, devs, and multisig signers. Everyone needs to be careful + stay skeptical. 🙏 x.com/i/web/status/1…
— Tay 💖 (@tayvano_)
12:16 PM • Dec 28, 2024
How it works / what we've seen:
Usually starts with a "recruiter" from known company e.g. Kraken, MEXC, Gemini, Meta.
Pay ranges + messaging style are attractive—even to those not actively job hunting.
Mostly via Linkedin. Also freelancer sites, job sites, tg, discord, etc. x.com/i/web/status/1…
— Tay 💖 (@tayvano_)
12:16 PM • Dec 28, 2024
While the fix might seem straightforward, Tay warns that these solutions can vary based on your operating system (Mac/Windows/Linux) and often lead to more harm than good. Specifically:
False Solutions: Following the provided instructions may prompt your browser (e.g., Chrome) to update or restart, but this doesn't resolve the original issue. Instead, it can introduce vulnerabilities or further complications.
Malicious Actors: Cybercriminals exploit these scenarios by crafting deceptive fix instructions that trick users into executing harmful commands, leading to potential data breaches, malware infections, or complete system compromise.
Granting perms does turn your video on. Like, green light goes on. But nothing else happens.
Luckily, there's now a helpful "How to fix" link
Sometimes this goes to a forum or GH issue and a comment there tells you "how to fix"
In this case it was in a modal on the site.
— Tay 💖 (@tayvano_)
12:16 PM • Dec 28, 2024