Key takeaways: What to know before you read
- Attackers use fake job candidates to deliver infostealer malware.
- There are two playbooks: fraud that comes through your hiring process and fraud aimed at your employees, especially developers.
- Cybersecurity experts advise isolating coding assessments and starting new hires on provisional, least privilege access.
- LastPass Business Max supports the credential security side: A vault with credential autofill plus capabilities like SaaS Monitoring, AI Monitoring, Web Monitoring, Web Protect, and enterprise Dark Web Monitoring to identify potential exposure and protect your organization.
- LastPass doesn’t read or monitor employee content. The capabilities are designed to help you manage SaaS and AI access, simplify identity security, and eliminate the friction that slows work down and puts your business at risk.
Before we go further, this isn't an article about employee retention. The new hire screening process is the delivery mechanism, not the actual threat.
Attackers have learned that technical interviews are fair game for a little sleight of hand. What starts as a job assignment quickly becomes a malware delivery chain for deploying infostealers, backdoors, and other payloads.
A fake recruiter might say, "Clone this repository, install the npm dependencies, and run the app for your JavaScript test assignment tomorrow." And because the npm package is hosted on a trusted platform like GitHub or GitLab, the job seeker readily trusts it.
However, hidden inside the npm package is a backdoor operating as a C2 beacon capable of delivering info like host device names, IP addresses, and other network identifiers back to a C2 server. This beacon can also execute attacker supplied payloads, collect credentials, and exfiltrate the collected data via outbound HTTP(S) POST requests.
The above is a favorite tactic of DPRK-linked WaterPlum (also known as "Contagious Interview"); Microsoft Defender Experts have been tracking this group's campaigns since December 2022.
Meanwhile, Lazarus associate TraderTraitor has been tied to fake Terraform test assignments designed to ensnare high-value professionals like developers and cloud admins. And that's because just one developer workstation with privileged credentials can serve as a valuable bridge into production environments and CI/CD pipelines.
According to NBC, DPRK operatives are even recruiting proxies in Iran, Syria, Saudi Arabia, and South Africa to establish in-person contact and obtain work contracts.
This is a creative workaround designed to defeat identity checks and establish trust, as some proxies are developers themselves who can credibly discuss the work and pass in-person coding assessments. And the ruse appears to be working.
NBC reports that, since 2024, at least 14 Iranian recruits have applied for jobs on behalf of DPRK agents and at least two received formal offer letters from U.S. employers after successful interviews.
Ultimately, recruitment workflows are being weaponized to steal credentials, exfiltrate intellectual property, and establish funding channels for weapons programs.
|
How are attackers using AI in the new hire screening process to compromise organizations?
Synthetic identities constructed with AI-generated documents, voice alteration, and deepfake video are actively exploiting gaps in the new hire screening process.
Instead of throwing the dice on phishing emails, attackers are:
In 2026, Insikt Group researchers identified at least 22 fabricated personas tied to the IT worker threat cluster "PurpleDelta." Between 2024 and 2025, PurpleDelta submitted as many as 60+ applications per day, across 8 job platforms, to 1,100+ companies across the healthcare, software, staffing, and financial sectors.
PurpleDelta operators used multiple Chrome profiles, ChatGPT, and real-time AI transcription tools to present themselves as credible candidates, sometimes repeating AI-generated answers verbatim.
Once hired, earnings were funneled through individual co-conspirators, shell organizations, and money-laundering front companies to finance rogue weapons programs.
Source: Recorded Future (Aug 2026)
|
What are the biggest recruitment fraud threats organizations face in 2026?
1. AI-generated candidates and identity fraud
Organizations are increasingly encountering candidates who use AI-generated resumes, synthetic identities, and personas during interviews. 69% of UK hiring leaders say AI-enabled or deepfake impersonations are the top threats to recruitment integrity.
2. Fake career portals and credential theft
Attackers create convincing copies of career sites to collect employment credentials, MFA codes, and personal info. In Aug 2026, CTM360 researchers uncovered 3,000+ phishing URLs from a campaign impersonating real recruiters from 50+ organizations across 14 sectors.
Each attack began with an unsolicited recruiting email and then a redirection to one of two flows: a fake Calendly-style page or branded recruitment portal. Both flows led to a "Continue with Google/Facebook" authentication pop-up with spoofed address bar and padlock. Once victims entered their login credentials, the attackers used them to log in to the real platforms.
3. Malware delivered through recruiting workflows
Fake coding or technical assessments are increasingly being used to trick developers into executing malicious code.
In campaigns uncovered by Microsoft, victims were instructed to download npm packages containing obfuscated payloads that installed infostealer malware, backdoors, or remote-access trojans (RATs) on work devices.
In 2025, a Maryland man was sentenced to 15 months in prison for allowing a North Korean national in China to work on software development contracts for the Federal Aviation Administration.
The same man even managed to obtain employment at 13 different U.S. companies, which netted him more than $970,000 in salary for software development services. Ironically, he didn't do the work; his overseas conspirators did.
How does a modern job fraud playbook work?
The above threats ultimately stem from two broader attack playbooks. One turns your hiring process into an entry point, while the other tricks your employees into becoming unwitting accomplices.
Playbook #1: When fraud gets through your new hire screening
Here, the attacker seeks you out for employment. The candidate uses a stolen identity, falsified documents, and an AI-altered voice on the video call to get through your screening process and get hired. Once they onboard into your HRIS platform, they're embedded in your system with legitimate credentials and all the privileges that come with them.
In 2026, researchers at Elastic Security Labs uncovered a "Contagious Interview" campaign (tracked as REF9403) where attackers hid malware inside SVG image files.
The researchers uncovered this campaign after members of their community Slack began receiving unsolicited job offers.
The researchers uncovered this campaign after members of their community Slack began receiving unsolicited job offers.
Those who responded and ran the “coding challenge” came away with an OTTERCOOKIE infection, which delivered a four-stage payload to their devices: a browser credential & crypto wallet stealer, a file stealer, a Socket.IO-based remote access trojan (RAT), and a clipboard stealer.
What to watch for:
- The candidate resists or repeatedly postpones video calls. If they attend, they may use altered feeds or face-masking technology (CNN).
- Interview questions are repeated almost verbatim, and answers arrive with a slight delay, as if they are being read off a script.
- Documents that support their candidacy contain metadata inconsistencies.
- Profile photos are enhanced with AI tools and used to replace images in stolen employment and identity documents.
- You get requests to use hardware you didn't provision, such as an IP-KVM device "for connectivity reasons." In 2025, Google warned admins that threat actors overseas are using IP-KVMs to remotely operate U.S.-based laptops, so corporate systems think online activity is originating from legitimate company-issued laptops.
- The candidate provides an address that doesn't match their login location once they're on the job.
Playbook #2: When the fraud targets your employees
Here, the attacker recruits you, or rather, your developers. Fake recruiters for AI, crypto, or NFT companies reach out through real platforms and ask a member of your team to complete a "coding assignment" or "environment fix" that delivers the malware payload.
What to watch for:
- There’s pressure to skip normal identity checks and hiring processes.
- The technical assessment is delivered via a private repository, ZIP archive, or local IDE project, rather than through recognized assessment platforms like HackerRank, CodeSignal, or Codility.
- The recruiter sends explicit instructions to disable antivirus programs or run with elevated permissions "to get the test working."
- The company in question has a “thin” web presence and there are discrepancies on their LinkedIn page.
- The pay feels disproportionate to the effort asked.
Why do careful, skilled professionals fall for this?
Instead of outright deception, which may be easier to catch, the playbooks above leverage trust in the workflows we've always relied on.
A multi-stage interview process can create the appearance of legitimacy, leading to sunk cost thinking: After the hours invested, backing out at the final "technical step" feels awkward and counterintuitive.
For both playbooks, there's a power dynamic that bears mentioning. The fake job recruiter makes caution feel professionally risky. They manufacture urgency ("we're close to making the final decision") to suppress your employee's suspicions and reframe unsafe actions as "normal" and evidence of technical competence.
And your hiring managers moving fast to fill a role rarely stop to ask critical questions of a candidate who's already cleared several rounds. The playbook works by using the parts of a hiring process everyone's trained not to question.
|
Why is recruitment fraud also a credential security problem?
Because the objective is access.
Attackers post fake job opportunities to lure job seekers into sharing the credentials that will get them access to source code repositories, internal systems, and SaaS platforms.
Once stolen, these credentials frequently appear in infostealer logs that are bought, sold, and reused by other threat actors. Recruitment fraud is therefore no longer just about a fraudulent hire or fake recruiter. It's often the first step in a much larger identity-compromise attack chain.
Visibility is the weak spot: 92% of organizations say employees use AI, but only 22% can log or monitor that usage (LastPass 2026 State of AI and SaaS Security Report).
Organizations that monitor credential exposure and unusual account activity are better positioned to identify compromised accounts before attackers can use stolen credentials to move laterally through corporate systems.
|
What can your organization do about this?
You can't vet every recruiter who messages your team or catch every fake resume before it lands in your hiring portal. But you can control how much each intrusion attempt costs you. In addition to deploying isolated interview environments and monitoring developer endpoints as Microsoft has advised, the table below shows how LastPass Business Max capabilities can help.
|
Control
|
What to do
|
Where LastPass helps
|
|
Start new hires on provisional access
|
Grant minimum access until identity checks finish.
|
SaaS Monitoring and AI Monitoring show which SaaS and AI apps credentials reach, so provisional access remains provisional.
|
|
Keep credentials out of browsers
|
Store secrets in a vault.
|
LastPass AES-256 encrypted vaults help reduce reliance on browser storage, which can be targeted by infostealers.
|
|
Block known phishing links or sites by category
|
Apply a category rule to block career and job recruitment portals
|
LastPass Web Protect makes a fake recruiter's malicious link useless.
|
|
See where exposure happened
|
Find out which sites, business/SaaS apps, and AI tools your team has been accessing
|
LastPass Web Monitoring, SaaS Monitoring, and AI Monitoring show you where credentials were used, so you know what to reset.
|
How do you decide if LastPass Business Max fits your team?
LastPass Business Max is a good fit if:
- You want compromised work credentials to give an attacker as little access as possible, and you want governance controls that don't monitor employee personal communications.
- You don't have a dedicated security team, and you want to manage web and AI controls in the same console as your credentials.
- You need to demonstrate SaaS and AI access governance to the board, leadership, or an insurer.
Note: LastPass Business Max isn't a replacement for endpoint protection, background check services, or a full DLP, SSPM, or CASB (but it can complement these controls).
Ultimately, the new hiring process will continue to be a target heading into 2027. But you have options to decide how little the attacker gets.
Find out which apps employee logins reach today, so if any laptops are infected tomorrow, you know which logins to shut off. Start your 14-day LastPass Business Max trial and see the logins in your Admin Console (no new hardware, agents, or proxies to install).
FAQ: Job fraud and credential stealing malware
How do I protect my business from spyware and infostealers?
No solution can stop every spyware or infostealer infection. But you can reduce risks to your organization with FIDO2 phishing resistant MFA, autofill, web-filtering controls, and credential exposure monitoring.
Business Max adds Web Monitoring [website discovery], Web Protect [malicious site blocking + website usage rules by category], SaaS Monitoring, AI Monitoring [shadow AI tool discovery], and enterprise Dark Web Monitoring to help your organization identify exposure earlier and reduce opportunities for attackers to exploit stolen credentials.
If an employee logs in to a work app with a personal Gmail account, will LastPass SaaS Monitoring capture that login?
In many cases, yes. LastPass SaaS Monitoring surfaces which SaaS or business apps are being accessed in the browser, including apps accessed with personal email addresses.
This LastPass capability doesn't monitor personal email activity or content but surfaces which business workflows may be extending beyond approved systems.
Similar visibility is available for AI usage through LastPass AI Monitoring [Shadow AI tool discovery], to identify which AI tools are being used across your organization, including tools adopted outside formal channels.
Does SaaS Monitoring and AI Monitoring count as employee surveillance?
No. SaaS Monitoring and AI Monitoring are designed for app access governance, not employee surveillance.
For example, AI Protect [AI usage guidance] doesn't log AI prompts, and Web Monitoring [Website Discovery] categorizes domains rather than capture page content.
These capabilities are intended to provide insight into where credentials or business systems may be exposed, so you can apply the appropriate governance controls. They can't (and don't) track employee productivity or personal behavior.
How can my organization identify shadow AI use during hiring and recruiting?
During the recruitment process, your hiring team may use AI tools to review resumes, draft communications, or evaluate technical submissions. AI Monitoring [shadow AI tool discovery] provides visibility into which AI tools are being accessed, including tools adopted outside IT oversight.
How can my organization reduce risk from recruitment phishing websites?
Recruitment scams often leverage fake career portals, calendar scheduling pages, and recruiter websites designed to steal credentials or distribute malware.
Business Max Web Protect [malicious site blocking + website usage rules by category] can help reduce risk by blocking known phishing sites, while Web Monitoring [website discovery] provides visibility into websites being accessed across your organization.
Together, these capabilities help identify potential exposure, so you can put the right controls in place to prevent a single interaction from becoming a larger security incident.
How can enterprise Dark Web Monitoring help detect recruitment-based credential theft?
When infostealer malware compromises a job candidate or employee device, the stolen data often includes usernames, passwords, and API keys. These credentials frequently surface in infostealer logs and Dark Web marketplaces before they're used in follow-up attacks.
LastPass enterprise Dark Web Monitoring can help identify exposed employee credentials earlier, enabling password resets before attackers gain broader access. Combined with credential security controls and SaaS monitoring, this visibility can reduce the impact of recruitment-themed phishing and malware campaigns.
Sources
The Hacker News: CTM360 uncovers over 3,000 recruitment phishing URLs using BitB credential traps (2026)



