زیرو اسٹوریج ہنگامی تحفظ: آپ کے اپ لوڈ کردہ شواہد صرف عارضی میموری میں پروسیس ہوتے ہیں اور فوری طور پر ختم کر دیے جاتے ہیں۔ کوئی لاگ یا کلاؤڈ بیک اپ نہیں۔

Cyber Espionage Vectorخطرے کی شدت کی سطح: انتہائی نازک

LinkedIn Fake Recruiter & Headhunter Detector: Spotting Infiltration Bots

Defending engineers and defense contractors from North Korean and state-sponsored recruiter malware campaigns.

Sealed Rose کے ساتھ میڈیا کی تصدیق کریں

فوری نیورل تجزیہ · مفت · کسی اکاؤنٹ کی ضرورت نہیں · زیرو اسٹوریج · میموری میں فوری تجزیہ

تصویری ڈیپ فیک کی تصدیق کریں

State-sponsored threat actors (such as Lazarus Group) create thousands of fake LinkedIn recruiter profiles with AI-generated headshots. They reach out to software developers, defense contractors, and Web3 engineers with lucrative job offers, asking them to clone a GitHub repo or execute a coding challenge that installs remote access trojans (RATs).

اہم خطرے کے اشارے

1AI Headshot with Perfectly Centered Eyes

Headshot aligns with the StyleGAN/Midjourney eye-centering rule: pupils sit at the exact horizontal midpoint of the image canvas.

2Urgent Request to Run a Coding Challenge on Your Local Machine

They send a zip file or GitHub link containing obfuscated npm/pip dependencies with post-install malware scripts.

The "Contagious Interview" Malware Attack

  • Malicious Dependency Poisoning: The coding test includes a `package.json` with a malicious `preinstall` hook that exfiltrates browser cookies and SSH keys.

اپنا دفاع کیسے کریں اور اقدامات

مرحلہ 1

Run Recruiter Headshot Through Sealed Rose

Check for GAN/Diffusion face synthesis markers.

مرحلہ 2

Never Run Unvetted Candidate Code on Your Bare Metal

Always sandbox coding challenges in ephemeral cloud VMs or isolated containers.

اکثر پوچھے گئے سوالات

Why are fake recruiters sending coding tests?

They use coding tests as a trojan horse to deliver malware directly onto developer laptops, stealing API keys, crypto wallets, and proprietary source code.

23 زبانوں میں دستیاب: