Rust warns of fake job interviews carrying malicious payload
The Rust project warned that attackers are targeting contributors and crate owners with fake recruiter approaches and plausible LinkedIn profiles to compromise their devices and accounts. The tactics resemble North Korean fake interview campaigns that affected over 30,000 devices and stole more than $10 million.
- Attackers set up legitimate-seeming company profiles and LinkedIn presences
- Targets are pushed to install a fake audio codec or run a clipboard command
- Tactics mirror North Korean campaigns hitting 30,000+ devices and $10M
- Rust faced fake recruiting and the malicious arrayref crate earlier this summer
Read next
Security