LinkedIn Recruitment Phishing Analysis: A Targeted Attack Against Blockchain Engineers
In March 2025, attackers posed as recruiters on LinkedIn targeting blockchain engineers, sending them Bitbucket repositories containing malicious code. The malicious payload was hidden on line 46 of server.js behind an extremely long horizontal scrollbar, encrypted through multiple layers of base64, and ultimately connected to a C2 server to download an info-stealing trojan and a persistence backdoor.