That NFT job offer is probably malware

Trojan
(Image credit: Iaremenko Sergii / Shutterstock)

Unknown threat actors have been discovered targeting graphic designers and artists with infostealer trojans, security researchers have revealed.

Artists from popular sites such as DeviantArt and Pixiv have been getting multiple messages claiming to offer potentially lucrative job roles. However, the job offer is just a disguise, as the sender’s true goal is to distribute an information-stealing trojan with a “good chance” of not being spotted by antivirus solutions.

Info-stealers usually grab passwords and other identity-related data stored in browsers, as well as cryptocurrency wallets, credit card data, and similar. 

Share your thoughts on Cybersecurity and get a free copy of the Hacker's Manual 2022end of this survey

Share your thoughts on Cybersecurity and get a free copy of the Hacker's Manual 2022. Help us find how businesses are preparing for the post-Covid world and the implications of these activities on their cybersecurity plans. Enter your email at the end of this survey to get the bookazine, worth $10.99/£10.99.

A job offer, or trojan?

In the job offer, the artist is invited to work on an NFT project. NFTs, or non-fungible tokens, in this context, are pieces of art stored on the blockchain. Lately, they’ve been enjoying enormous popularity and dizzying valuations (some are worth tens of millions of dollars).

In the offer, the artist will be told what’s expected of them, will be asked for their CV or resume, and will be given a link with examples of previous NFT work by the project managers. That link, for which the attackers say is essentially the project’s style guide, leads to a password-protected RAR archive named 'Cyberpunk Ape Exemples (pass 111).rar.

The archive does carry a few low-res images, but also carries a well-hidden .EXE file. At first glance, it appears to be a .GIF file, but is, in fact, malware.

While infostealers can do all kinds of damage, and steal all kinds of information, in this context it’s safe to assume that the attackers could be after the artists’ cryptocurrency wallets, especially if they’ve been involved in NFT projects in the past. Crypto projects usually pay their team members, employees, and collaborators, in cryptocurrencies.

Cyberpunk Ape project leaders took to Twitter to distance themselves from this campaign, saying the job offer is not real.

“Don't respond. Don't click the link. Report the people who are doing this on the platform they contact you on,” the Twitter post reads.

Via: BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A digital representation of a lock
Looking for a new job? Watch out you don't fall for this new malware scam
Red padlock open on electric circuits network dark red background
CrowdStrike warns of fake job offer scam that is actually just malware
Trojan
Hackers hide malware into website images to go unnoticed
A digital representation of a lock
Security experts are being targeted with fake malware discoveries
botnet
YouTubers targeted by blackmail campaign to promote malware on their channels
Representational image of a cybercriminal
Criminals are spreading malware disguised as DeepSeek AI
Latest in Security
ransomware avast
Ransomware attacks are costing Government offices a month of downtime on average
Lock on Laptop Screen
Data breach at Pennsylvania education union potentially exposes 500,000 victims
Data leak
Top collectibles site leaks personal data of nearly a million users
Spyware
Stalkerware data breach potentially hits over 2 million users, including thousands of Apple devices
An American flag flying outside the US Capitol building against a blue sky
Five Eyes "cannot replace US intel in Ukraine", claims former US Cyber Command Chief
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Criminals are using a virtual hard disk image file to host and distribute dangerous malware
Latest in News
Wonka poster
Netflix cooks up sweet new reality TV series based on Charlie and the Chocolate Factory, and it's a dream come true for me
Citroen 2CV
The retro EV resurgence is in full swing, as Citroen confirms the iconic 2CV will return with batteries
Hugging Snap
This AI app claims it can see what I'm looking at – which it mostly can
Apple iPhone 16 Pro Max REVIEW
The latest batch of leaked iPhone 17 dummy units appear to show where glass meets metal on the new designs
Hornet swings their weapon in mid air
Hollow Knight: Silksong could potentially launch this year and I reckon it could be a great game for an Xbox handheld
ransomware avast
Ransomware attacks are costing Government offices a month of downtime on average