Sıfır Saxlama Böhran Mühafizəsi: Yüklənmiş sübutlar yalnız əməli yaddaşda təhlil edilir və dərhal məhv edilir. Heç bir qeydiyyat və ya bulud nüsxəsi saxlanılmır.
LinkedIn Fake Recruiter & Headhunter Detector: Spotting Infiltration Bots
Defending engineers and defense contractors from North Korean and state-sponsored recruiter malware campaigns.
Sealed Rose ilə Medianın Həqiqiliyini Yoxlayın
Dərhal Neyron Şəbəkə Skanlaması · Pulsuz · Qeydiyyat Tələb Olunmur · Sıfır Saxlama · Yaddaşda Emal
State-sponsored threat actors (such as Lazarus Group) create thousands of fake LinkedIn recruiter profiles with AI-generated headshots. They reach out to software developers, defense contractors, and Web3 engineers with lucrative job offers, asking them to clone a GitHub repo or execute a coding challenge that installs remote access trojans (RATs).
Kritik Xəbərdarlıq Əlamətləri
1AI Headshot with Perfectly Centered Eyes
Headshot aligns with the StyleGAN/Midjourney eye-centering rule: pupils sit at the exact horizontal midpoint of the image canvas.
2Urgent Request to Run a Coding Challenge on Your Local Machine
They send a zip file or GitHub link containing obfuscated npm/pip dependencies with post-install malware scripts.
The "Contagious Interview" Malware Attack
- Malicious Dependency Poisoning: The coding test includes a `package.json` with a malicious `preinstall` hook that exfiltrates browser cookies and SSH keys.
Özünüzü Qorumaq və Addımlar
Run Recruiter Headshot Through Sealed Rose
Check for GAN/Diffusion face synthesis markers.
Never Run Unvetted Candidate Code on Your Bare Metal
Always sandbox coding challenges in ephemeral cloud VMs or isolated containers.
Tez-tez Verilən Suallar
Why are fake recruiters sending coding tests?▼
They use coding tests as a trojan horse to deliver malware directly onto developer laptops, stealing API keys, crypto wallets, and proprietary source code.
23 dildə mövcuddur: