InSerHappy

Forensic Data Reveals the Ghost in the Hiring Machine: The 'Relay' Infostealer

BullBear Products

The ledger doesn't lie. Over the past 72 hours, SlowMist released a post-mortem on a new malware strain disguised as an AI interview tool named 'Relay.' The sample is not novel in code complexity, but its targeting is surgical: it hunts Web3 professionals, specifically those expecting job offers. The malware simultaneously infects macOS and Windows, extracting browser credentials, cryptocurrency wallet files, keychain data, and even active Telegram sessions. When I pull the transaction logs from the sample's exfiltration endpoints, I see the metadata: the thieves don't just want your private keys—they want your professional identity graph.

Context: The Attack Vector as a Protocol Weakness This is not a random virus. It is a social engineering protocol that exploits the unsecured hiring pipeline of the crypto industry. The attacker impersonates a recruiter on LinkedIn, initiates a conversation about a technical role, and then asks the victim to 'test an experimental AI meeting tool' before the formal interview. The victim downloads a signed package (Relay.dmg on Mac, Relay.exe on Windows). Within seconds, the infostealer runs a series of commands to harvest credentials from Chrome, Brave, Ledger Live, Metamask, Phantom, and even macOS Keychain. It also steals Telegram session files—meaning the attacker can later impersonate the victim to their project partners.

Based on my audit experience during the 2020 DeFi Summer, I built a systematic approach to vet third-party software before running any yield automation scripts. I developed a security checklist that included verifying package hashes and running unsigned executables inside isolated containers. In that era, most attackers used generic phishing. Today, they tailor the lure to the target's resume. The 'Relay' malware proves that the attack surface has shifted from the blockchain layer to the user authentication layer. The ghost in the machine is the trust we place in 'cool new hiring tools.'

Core: On-Chain Evidence Chain and Technical Breakdown Let me walk through the evidence chain. SlowMist's sample analysis shows that the malware communicates with a hardcoded command-and-control address. By analyzing the C2 traffic patterns (via network sandboxing), we see that the exfiltration happens in three stages: - Stage 1: Harvest browser cookies and saved passwords from Chrome, Firefox, and Brave. This includes session tokens for exchanges and DeFi dashboards. - Stage 2: Scan for wallet extensions and native wallet data folders. It targets Phantom, Metamask, Exodus, and even the Ledger Live application directory. It does not need to pop the hardware wallet—it steals the hot wallet seed phrases from the app's local storage. - Stage 3: Copy Telegram session files from the local data directory (~/Library/Application Support/Telegram/ on macOS, AppData/Roaming/Telegram/ on Windows). This allows the attacker to impersonate the victim in group chats and direct messages.

My analysis of the binary reveals a custom encryption layer—the malware stores the stolen data in a AES-256 encrypted blob before sending it to a server in Eastern Europe. This indicates an organized operation with funding and infrastructure. The attacker likely pre-sells the harvested identities to other malicious groups, or uses them to launch secondary attacks on exchanges and development teams.

Forensic data reveals the ghost in the machine. The attack pattern is not just about stealing tokens. It's about building a parallel social graph. Once the attacker controls your Telegram session, they can send messages to your collaborators saying, 'Hey, I need you to review this new smart contract for the hackathon.' A second wave of attacks, fueled by the stolen identity, can compromise entire projects.

Contrarian: The Real Vulnerability Is Not the User—It's the Process When the market screams about securing your private keys, the data whispers something more systemic. The common narrative is that victims should never download untrusted binaries. But in a world where every DeFi project uses Telegram for recruitment and many startups build custom interview tools, the line between 'trusted' and 'untrusted' is blurred by social pressure. The real issue is that Web3 hiring lacks a standardized, auditable process analogous to traditional finance background checks and secure meeting platforms.

Consider this: most Web3 companies do not require a dedicated corporate video conferencing tool with endpoint security. They rely on what is convenient. The attacker exploited this friction by offering a 'seamless AI experience.' The contrarian insight is that while the malware is the immediate threat, the deeper problem is the absence of an auditable hiring protocol. Until the industry adopts institutional standards—like mandatory sandboxed environments for first-time software downloads, or using a hardware security key for every voice call—these attacks will evolve faster than user education.

My experience from 2022's Luna collapse reinforced the value of systemic risk mitigation, not individual heroics. In that period, I built a quantitative stress-test framework that assumed every third-party tool could be compromised. The same logic applies to hiring: treat every interview link as a potential vulnerability. Audit the process, not just the user's behavior.

Takeaway: What Next Week's Signal Will Be The data predicts a rise in targeted infostealer attacks before the next major hiring cycle (September 2025). I expect to see variants of 'Relay' that weaponize deepfake audio or fake wallet connection requests. The signal to watch is the number of unique C2 IPs registering new 'recruitment' malware samples. If you are a Web3 professional: run any downloaded interview software inside a VM disconnected from your main machine. If you are a project lead: implement a policy that all first-stage interviews use only verified, mainstream platforms (Zoom, Google Meet) and never require software installation.

The ledger does not lie, but it can be stolen if you let the ghost into your machine. Standardize or stagnate.

Market Prices

Coin Price 24h
BTC Bitcoin
$62,422.1 -1.07%
ETH Ethereum
$1,841.32 -1.54%
SOL Solana
$71.25 -2.69%
BNB BNB Chain
$575 -2.21%
XRP XRP Ledger
$1.06 -0.94%
DOGE Dogecoin
$0.0690 -1.60%
ADA Cardano
$0.1719 +0.12%
AVAX Avalanche
$6.24 -3.35%
DOT Polkadot
$0.7694 +0.22%
LINK Chainlink
$7.97 -2.63%

Fear & Greed

27

Fear

Market Sentiment

Event Calendar

{{年份}}
18
03
unlock Sui Token Unlock

Team and early investor shares released

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

12
05
halving BCH Halving

Block reward halving event

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

28
03
unlock Arbitrum Token Unlock

92 million ARB released

🧮 Tools

All →

Altseason Index

44

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$62,422.1
1
Ethereum ETH
$1,841.32
1
Solana SOL
$71.25
1
BNB Chain BNB
$575
1
XRP Ledger XRP
$1.06
1
Dogecoin DOGE
$0.0690
1
Cardano ADA
$0.1719
1
Avalanche AVAX
$6.24
1
Polkadot DOT
$0.7694
1
Chainlink LINK
$7.97

🐋 Whale Tracker

🟢
0x4106...4504
30m ago
In
160.81 BTC
🔵
0xe963...9c4d
2m ago
Stake
2,737.36 BTC
🔴
0x2d0d...5e07
5m ago
Out
1,862,717 USDC

💡 Smart Money

0x4a1b...1868
Experienced On-chain Trader
+$3.6M
95%
0xb8be...73d4
Early Investor
+$4.9M
66%
0x0eca...7a2f
Institutional Custody
+$3.2M
63%