SlowMist flags Relay recruitment scam targeting Web3 workers on macOS and Windows

SlowMist flags Relay recruitment scam targeting Web3 workers on macOS and Windows

Attackers posing as recruiters are using a fake AI interview app to steal browser logins, wallet data, Telegram sessions and macOS Keychain contents, with Windows samples also designed to persist after reboot.

Fact Check
The claim is confirmed directly by the primary source. SlowMist's official X account (@SlowMist_Team) posted the alert on 2026-07-29, describing a job scam targeting Web3 professionals via malware disguised as an AI meeting tool called 'Relay' on macOS and Windows, stealing browser credentials, wallet-related information, Keychain data, and Telegram sessions. The linked SlowMist Medium technical report provides the full attack chain, installer names, and IOCs. Three independent crypto news outlets (PANews, BlockBeats, Odaily) corroborate every element of the claim.
Summary

SlowMist said on July 29 it identified a recruitment scam aimed at Web3 workers, with attackers impersonating recruiters and directing targets to relay.lc to install a fake AI meeting platform called Relay. The campaign uses polished recruiter outreach and a credible-looking interview workflow to deliver malware on both macOS and Windows. Researchers said the installers contain no genuine meeting functions and instead harvest browser credentials, wallet-extension data, Telegram sessions, system information and, on macOS, login Keychain contents paired with a password captured through a fake error dialog. The Windows sample uses a simulated update screen, seeks administrator privileges and is built to persist through Registry and Startup-folder entries, while the macOS variant appears focused on rapid one-time exfiltration during the interview window. SlowMist’s MistEye platform classified the site as high-risk after community reports, and the firm said the operation fits a broader pattern of interview-based crypto theft campaigns targeting professionals likely to hold hot-wallet assets and sensitive credentials.

Terms & Concepts
  • social engineering: A tactic that manipulates people into taking actions such as installing malware or sharing sensitive information.
  • Keychain: Apple’s macOS credential store for passwords, keys and other protected secrets.
  • persistence: A malware capability that lets malicious software remain active or restart after a system reboot.