Singapore authorities reported a scam campaign that stole approximately $11.8 million (S$15.1 million) from cryptocurrency firms. Attackers posed as recruiters on LinkedIn and targeted employees at crypto firms with fake job offers including technical assessments containing malware. This malware stole session tokens to bypass multi-factor authentication and access the code repositories of targeted companies. The fraudsters then modified software to remove transaction limits and divert crypto funds. Authorities said the campaign is ongoing and other firms may be at risk.
Source: Read the original article

