Beware LinkedIn Job Offers: Hackers Pose as Recruiters and Send Data-Stealing Tests
Translated from Romanian and summarized by DistantNews. Read the original for the full story.
At a glance
- Hackers posing as recruiters on LinkedIn are targeting software engineers in the aviation and financial technology sectors.
- Victims receive programming tests hosted on a legitimate Amazon online storage service, but downloaded files can contain malware that enables remote access.
- Researchers identified two tools, NodeRabbit and PollCat, linked to the Mirage Kitten group and capable of helping attackers control systems and extract data.
A job offer on LinkedIn can conceal a trap. Hackers are contacting software engineers in aviation and financial technology while posing as recruiters from major companies.
The approach begins with a familiar message: a candidate is told about an employment opportunity and invited to complete a technical assessment. The candidate then receives a link to download a programming test. Because the file is hosted on a legitimate Amazon storage service, it may appear to be part of a normal recruitment process.
The attackers add pressure by giving candidates only one to three hours to finish. They also tell them not to use artificial intelligence-based coding assistants. That instruction may sound plausible in a genuine hiring process, but in this campaign it also prevents victims from using a tool that could flag suspicious elements in the test files.
The candidate is left with little time and a technical exercise to complete. After downloading and opening the file, the hidden program can begin operating on the computer without the victimโs knowledge. Researchers linked the attacks to the Mirage Kitten group and identified two newer tools, NodeRabbit and PollCat. Both can give attackers remote access, allowing them to control certain system functions, search for information and send data outside the computer. NodeRabbit is hidden in software packages that may look normal to programmers and attempts to remain on the device after installation.
Originally published by Adevฤrul in Romanian. Translated, summarized, and contextualized automatically by DistantNews, with a note on how the source frames the story. Not individually reviewed before publishing. How this works.