Deception Scenario How Inverted Social Engineering is Redefining the Web3 Recruitment Trap
Hackers are shifting tactics. Learn how fake Web3 job postings and malicious interview apps are used to compromise high-value crypto…
Deception Scenario How Inverted Social Engineering is Redefining the Web3 Recruitment Trap

Deception inverted Social Engineering
In the cybersecurity landscape, we are witnessing a tactical pivot. For years, social engineering followed an “outbound” model attackers would hunt victims through phishing or cold outreach.
Recently, I discover new sophisticated scenario of threat actors. They aren’t hunting anymore, they are setting traps and letting high-value targets walk right in.
This “inbound” strategy is currently targeting the Web3 and Cryptocurrency sectors with alarming success.
The Psychology of the “Pull” Strategy
The logic is simple but devastatingly effective. By creating high-fidelity fake companies or cloning legitimate Web3 firms, attackers post job openings for lucrative roles using website youbuidl.dev.

youbuidl invitation email
This creates a psychological advantage:
- Lowered Defenses: When a victim applies for a job, they are the ones seeking an opportunity. This eliminates the initial suspicion that usually arises when a stranger reaches out via LinkedIn or Telegram.
- The “Jackpot” Target: The individuals applying for these roles who likely have personal crypto wallets on their devices. Even better for the attacker, many applicants use their current corporate laptops to conduct their job search. If that applicant works for a crypto exchange or a DeFi protocol, the attacker gains a direct bridge into a major financial entity.
The “Meeting App” A Trap Case Study
The execution of this campaign mirrors a standard corporate recruitment workflow. After applying, the candidate receives a professional email invitation for a interview. In recent observations, attackers have utilized domains like collaborex.ai.

collaborex ai
The trap is sprung during the “Join Meeting” phase. The victim got prompted to download a proprietary desktop application.

collaborex invitation email
The file was downloaded named collaborex_setup.msi Once the app is executed, on the background it try to initiates a Command & Control (C2) connection to the attacker IP 179.43.159.106 , allowing for full system compromise and data exfiltration.
Reference Cases
This technique is not an isolated incident. It is a refinement of tactics used by some of the world’s most persistent threat actors:
- Operation Dream Job (Lazarus Group) Attributed to North Korean state-sponsored actors, this long-running campaign has historically used fake job offers on LinkedIn to deliver malware to employees in defense and aerospace. The Web3 version is a direct evolution of this.
- BlueNoroff (SnatchCrypto) This sub-group of Lazarus has been known to target crypto startups by posing as venture capital firms or recruiters, often using malicious “meeting links” or “contract documents” to drain wallets.
- The “KANDYKORN” Campaign Recent reports show attackers targeting Discord users and developers with fake “automated trading bots” or “recruitment tasks” that install sophisticated macOS backdoors.
Protecting Yourself in the Job Market
As attackers become more professional in their “recruitment,” we must become more clinical in our verification:
- The Browser-Only Rule: Treat any requirement to download a .exe, .dmg, or .pkg file for a simple meeting as a critical red flag. Stick to industry-standard platforms (Zoom, Meet, Teams).
- Verify the Recruiter: Check the age of the company’s domain. A “leading Web3 firm” should not have a website that was registered only a few weeks ago.
- Hardware Isolation: If you are a high-value target, perform your job search on a dedicated, isolated machine that is not connected to your primary crypto wallets or corporate network.
Conclusion
The “Collaborex” case is a stark reminder that the greatest vulnerability isn’t always a bug in the code, it’s the human desire for a new opportunity. In the digital age, the job you apply for might be the very tool used to compromise your most sensitive assets.
메타데이터
- post_id
- f02b387cd6df
- slug
- deception-scenario-how-inverted-social-engineering-is-redefining-the-web3-recruitment-trap-f02b387cd6df
- url
- https://infosecwriteups.com/deception-scenario-how-inverted-social-engineering-is-redefining-the-web3-recruitment-trap-f02b387cd6df
- canonical_url
- https://infosecwriteups.com/deception-scenario-how-inverted-social-engineering-is-redefining-the-web3-recruitment-trap-f02b387cd6df
- author_url
- https://medium.com/@arisharyanto
- status
- ok
- fetched_at
- 2026-08-02 01:16:52