[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-linkedin-job-offer-link-can-trigger-hidden-code-execution":10,"sections":42},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":30,"persona_id":22,"persona_name":22,"section":31,"tags":32,"sources":37,"feedback":41,"feedback_at":22,"cost_usd":41,"total_tokens":41},977,"linkedin-job-offer-link-can-trigger-hidden-code-execution","LinkedIn Job Offer Hid a Backdoor","A personal account of how a convincing LinkedIn recruiter message turned out to be a delivery vehicle for malicious code.","A security researcher got a job offer through LinkedIn. It came with a backdoor.\n\nThe post, published on a personal blog, documents how what appeared to be a routine recruiter outreach turned out to be a vehicle for malicious code. The exact payload and delivery mechanics are not detailed in the available source, but the shape is familiar: a convincing professional lure followed by a file or link that installs software giving an attacker persistent access to the victim's machine. The researcher traced the connection back to the original LinkedIn message.\n\nThis kind of attack fits a pattern security teams have been flagging for years. Nation-state groups, most visibly those linked to North Korea's Lazarus cluster, have refined the fake-job-offer playbook into something close to an art form, targeting developers and security researchers with malware wrapped inside what looks like a skills assessment or a code sample to review. The technique works because it exploits the specific social logic of a job search: the target is motivated to engage, the recruiter has a plausible reason to send files, and skepticism feels like self-sabotage.\n\nWhat makes first-person accounts like this one valuable is that they put a human face on a threat that mostly lives in threat-intelligence PDFs. A real person got a plausible message, followed a reasonable chain of steps, and ended up with malware on their machine.\n\nLinkedIn keeps announcing improvements to fake-account detection and malicious-content removal. Posts like this one are a useful reminder of the distance between \"we're working on it\" and \"it's fixed.\"","[\"linkedin\",\"social-engineering\",\"malware\",\"backdoor\"]","2026-06-15T20:00:57.000Z","2026-06-15T20:33:04.966Z","2026-06-18T13:31:51.062Z","published",null,[24],{"id":25,"reviewer":26,"round":27,"reason":28,"status":29},"editor-r1","editor",1,"Add concrete details (researcher name, date of discovery, any technical specifics) and cite the original blog source more precisely; clarify that it is a proof‑of‑concept and not a known active exploit.","resolved","https:\u002F\u002Fcdn.xyz.onl\u002Farticle-images\u002Flinkedin-job-offer-link-can-trigger-hidden-code-execution.webp","security",[33,34,35,36],"linkedin","social-engineering","malware","backdoor",[38],{"name":39,"url":40},"Hacker News","https:\u002F\u002Froman.pt\u002Fposts\u002Flinkedin-backdoor\u002F",0,{"sections":43},[44,49,53,58,63,68,73,78,83,88,93,98,103,108],{"name":45,"slug":46,"count":47,"latest_published_at":48},"AI","ai",2602,"2026-07-18T18:30:00.000Z",{"name":50,"slug":31,"count":51,"latest_published_at":52},"Security",315,"2026-07-17T19:30:00.000Z",{"name":54,"slug":55,"count":56,"latest_published_at":57},"Deals","deals",179,"2026-06-29T20:02:07.000Z",{"name":59,"slug":60,"count":61,"latest_published_at":62},"Policy","policy",169,"2026-07-17T19:49:53.000Z",{"name":64,"slug":65,"count":66,"latest_published_at":67},"Hardware","hardware",126,"2026-07-16T20:09:48.000Z",{"name":69,"slug":70,"count":71,"latest_published_at":72},"Consumer Tech","consumer-tech",94,"2026-07-16T16:29:46.000Z",{"name":74,"slug":75,"count":76,"latest_published_at":77},"Software","software",72,"2026-07-17T09:42:05.000Z",{"name":79,"slug":80,"count":81,"latest_published_at":82},"Science","science",66,"2026-07-10T10:29:37.000Z",{"name":84,"slug":85,"count":86,"latest_published_at":87},"Dev Tools","dev-tools",60,"2026-07-16T16:59:13.000Z",{"name":89,"slug":90,"count":91,"latest_published_at":92},"Startups","startups",42,"2026-07-16T16:30:35.000Z",{"name":94,"slug":95,"count":96,"latest_published_at":97},"Gaming","gaming",41,"2026-07-09T04:00:00.000Z",{"name":99,"slug":100,"count":101,"latest_published_at":102},"General","general",29,"2026-07-10T22:28:58.000Z",{"name":104,"slug":105,"count":106,"latest_published_at":107},"Reviews","reviews",20,"2026-06-24T12:00:01.000Z",{"name":109,"slug":110,"count":111,"latest_published_at":112},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]