
Attackers posing as recruiters are using a fake AI interview app to steal browser logins, wallet data, Telegram sessions and macOS Keychain contents, with Windows samples also designed to persist after reboot.
SlowMist said on July 29 it identified a recruitment scam aimed at Web3 workers, with attackers impersonating recruiters and directing targets to relay.lc to install a fake AI meeting platform called Relay. The campaign uses polished recruiter outreach and a credible-looking interview workflow to deliver malware on both macOS and Windows. Researchers said the installers contain no genuine meeting functions and instead harvest browser credentials, wallet-extension data, Telegram sessions, system information and, on macOS, login Keychain contents paired with a password captured through a fake error dialog. The Windows sample uses a simulated update screen, seeks administrator privileges and is built to persist through Registry and Startup-folder entries, while the macOS variant appears focused on rapid one-time exfiltration during the interview window. SlowMist’s MistEye platform classified the site as high-risk after community reports, and the firm said the operation fits a broader pattern of interview-based crypto theft campaigns targeting professionals likely to hold hot-wallet assets and sensitive credentials.