

ANATOMY OF A FAKE INTERVIEW: Social Engineering Campaigns Targeting Crypto Developers
The CVA Cybersecurity Working Group is pleased to host its next event in person in Zug, at the Liquid Room at CV Labs.
This session will feature Niels Lachat from the Swiss Federal Department of Defence, Civil Protection and Sport (DDPS), National Cyber Security Centre (NCSC), Switzerland’s federal competence centre for cybersecurity and the first point of contact for businesses, public services, educational institutions and the population on cyber-related issues.
Crypto developers have become a prime target for a highly effective social engineering technique: the fake job interview. Posing as recruiters on LinkedIn and similar platforms, attackers lure developers into what appears to be a legitimate hiring process - culminating in a "coding exercise" that secretly delivers malware. Once installed, this malware can steal cryptocurrency wallets and credentials, and open the door to further lateral movement within a victim's systems or organization.
Agenda:
🔹 Introduction to the Cybersecurity Working Group · 10 min
🔹 Presentation · 30 min
🔹 Q&A and Discussion · 10 min
Moderated by Patrick Schramboeck
🔹 Apéro & Networking
This presentation walks through a typical fake interview campaign from first contact to compromise, illustrating the tactics attackers use to appear credible and the technical consequences when the ruse succeeds. It concludes with practical guidance: how to recognize red flags in recruiters and companies, how to safely handle unsolicited coding assignments (e.g. using single-use virtual machines), and what steps to take - including preserving evidence and reporting - if you believe you've been targeted.