Wednesday, July 29, 2026

SlowMist Warns Fake Interview App Is Targeting Web3 Job Candidates

Neon crypto security illustration: a candidate faces a fraudulent interview app delivering malware, with cyan lighting.

SlowMist has identified a recruitment scam that uses a counterfeit AI meeting application to infect Web3 professionals seeking new roles. Attackers pose as recruiters and direct candidates to install a fake interview tool branded as Relay, turning an apparently routine hiring step into a malware-delivery channel.

The campaign includes malicious software for both macOS and Windows systems, with SlowMist linking the samples to attempts to collect browser credentials, cryptocurrency wallet information, Keychain data and active Telegram sessions. This combination can expose personal accounts, digital assets and corporate systems through a single compromised device.

Fake Meeting Software Turns Hiring Into an Access Vector

The operation relies on the credibility of the recruitment process rather than a direct attack on a blockchain protocol. A candidate may receive realistic outreach, discuss professional experience and proceed toward a scheduled interview before being asked to install unfamiliar software. The interview itself becomes the delivery mechanism, reducing suspicion because video applications and troubleshooting steps are already common in remote hiring.

SlowMist has previously documented similar cases in which recruiters switched meeting platforms during a call and directed candidates to download another application when the replacement link appeared not to work. Victims who continued with the installation later experienced abnormal wallet activity. A fabricated technical problem creates urgency while making the requested installation appear necessary, rather than optional or suspicious.

The theft potential extends beyond saved passwords. Browser cookies and authenticated sessions may allow attackers to enter services without repeating the normal login process, while locally stored wallet files, extension data and credentials can support later asset theft. Browser sessions and wallet-related data can be combined into a broader account-takeover chain, particularly when one machine is used for work, communications and digital-asset management.

For cryptocurrency users, the critical distinction is that the failure occurs at the endpoint rather than onchain. A wallet contract, exchange or blockchain may continue operating normally while malware captures the credentials or signing material that gives its victim control over funds. Transactions authorized with stolen keys can still appear technically valid to the network.

The campaign also fits an established recruitment-malware pattern. Microsoft has tracked the related Contagious Interview operation since at least December 2022, documenting staged recruiter outreach, technical discussions and assignments that persuade candidates to execute malicious packages or commands. Modern hiring workflows are being treated as persistent attack surfaces, especially when developers routinely clone repositories, install dependencies or test unfamiliar software during evaluations.

Endpoint Controls Matter More Than Wallet Branding

Candidates should verify recruiter identities through a company’s established website, directory or independently sourced contact details before installing software. Interview applications should not be downloaded from recruiter-supplied links unless the publisher and distribution channel can be independently authenticated. SlowMist specifically advised users to exercise caution when installing software during online interviews or recruitment processes.

Developers who must test code or applications should use an isolated virtual machine or disposable device that contains no production credentials, private keys, exchange sessions or corporate access tokens. A device used for wallets or transaction signing should not double as an interview test machine. Microsoft recommends isolated interview environments and greater monitoring of developer endpoints, repositories and dependency execution.

Organizations can further reduce exposure through updated endpoint protection, multifactor authentication, least-privilege access and monitoring for unusual processes or network activity. Government cybersecurity guidance also recommends employee training, web filtering and network segmentation against ClickFix-style attacks, which manipulate users into executing malware under the pretext of fixing a technical problem. Security controls must assume that a convincing interface can still carry a hostile payload.

Anyone who executed a suspected installer should disconnect the device from the network, preserve relevant logs and seek professional incident-response support. Active sessions should be revoked and passwords rotated from a clean device. Changing a wallet password is not enough once a seed phrase or private key may have been exposed; affected assets should be moved to a newly generated wallet using an uncompromised system.

SlowMist has not disclosed a victim count, confirmed financial-loss total or attribution for the current Relay campaign. The campaign’s scale and operator therefore remain unresolved, even though the analyzed samples establish a credible threat to Windows and macOS users.

The immediate defensive priority is straightforward: treat unexpected interview-software installations as a security event, not routine troubleshooting. Remote recruitment may provide the initial trust, but the compromise begins only when malicious code is allowed to run on a candidate’s device.

Scroll to Top
Chain Report
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.