A security researcher got a job offer through LinkedIn. It came with a backdoor.
The post, published on a personal blog, documents how what appeared to be a routine recruiter outreach turned out to be a vehicle for malicious code. The exact payload and delivery mechanics are not detailed in the available source, but the shape is familiar: a convincing professional lure followed by a file or link that installs software giving an attacker persistent access to the victim's machine. The researcher traced the connection back to the original LinkedIn message.
This kind of attack fits a pattern security teams have been flagging for years. Nation-state groups, most visibly those linked to North Korea's Lazarus cluster, have refined the fake-job-offer playbook into something close to an art form, targeting developers and security researchers with malware wrapped inside what looks like a skills assessment or a code sample to review. The technique works because it exploits the specific social logic of a job search: the target is motivated to engage, the recruiter has a plausible reason to send files, and skepticism feels like self-sabotage.
What makes first-person accounts like this one valuable is that they put a human face on a threat that mostly lives in threat-intelligence PDFs. A real person got a plausible message, followed a reasonable chain of steps, and ended up with malware on their machine.
LinkedIn keeps announcing improvements to fake-account detection and malicious-content removal. Posts like this one are a useful reminder of the distance between "we're working on it" and "it's fixed."
