Cybersecurity News

Filters
Tag
Reset

Filtered by tag: clickonce × Clear

Fake Web3 Interview Uses Signed ClickOnce to Deploy NeedleStealer and hVNC RAT

Matched: cryptocurrency

Attackers posing as Web3 recruiters on LinkedIn lured cryptocurrency professionals into fake job interviews, ultimately tricking Windows users into installing malware via a signed ClickOnce application. The infection deployed NeedleStealer, which harvested private keys and browser data, alongside an hVNC remote access trojan. The campaign used Calendly scheduling and technical assessments to appear legitimate.