×

Relay Malware Uses Fake AI Meeting App to Target Crypto Wallets of Web3 Job Applicants

A malware strain known as Relay is reportedly using a fake AI meeting app to target the crypto wallets of Web3 job applicants, luring candidates through what appears to be a legitimate recruitment and interview process.

The threat centers on Relay malware, which security researchers describe as an information-stealing tool delivered through interview software presented to job seekers, according to a SlowMist threat intelligence report. The lure is a fake AI meeting application, and the stated victim group is applicants pursuing Web3 roles. For related coverage, see Emirates to Let UAE Residents Pay for Flights via Crypto.com.

The core of the campaign is social engineering rather than a blunt technical exploit. By dressing the malware as a meeting or interview tool that a candidate is asked to install, attackers exploit the trust built into a normal hiring workflow. The end objective is reaching the crypto wallets of the people who download it. For related coverage, see Tennessee County Passes Ban on Crypto Operations.

Why a Fake Meeting App Works Against Job Seekers

The fake AI meeting app is not a side detail; it is the entry point of the attack chain. In a Web3 hiring context, being asked to download interview or meeting software is routine, which is exactly what makes the request hard to question. For related coverage, see SEC and Crypto Initiative Exemptions: Balancing Regulation and Innovation.

Because the targets are job applicants, the malware rides inside a recruitment sequence rather than arriving as an unsolicited link. Similar recruitment-themed lures aimed at Web3 developers have been documented by security reporters covering fake recruiter campaigns targeting the sector. That framing gives the download an air of legitimacy that ordinary phishing lacks. For related coverage, see Crypto disputes: US arbitration group launches panel.

From there, the reported goal is the applicant's crypto wallet. The specific execution steps and wallet-drain mechanics are not detailed in the available research, so they are not stated here as fact.

What This Means for Web3 Hiring and Wallet Security

Web3 job applicants are a meaningful target because many of them already hold crypto and interact with wallets as part of their work. That overlap between the candidate pool and active wallet users is what makes the group attractive to attackers.

Wallet-focused attacks carry sharper consequences than routine credential phishing. Once wallet access is exposed, digital assets can be moved directly, a risk pattern also seen in cases like the lawsuit over a fake iPhone wallet app tied to an alleged Bitcoin theft.

The combination of fake AI tooling and recruitment language suggests attackers are adapting their lures to current technology and hiring trends. For both candidates and hiring teams in crypto, the practical takeaway is caution around any interview software an unverified recruiter asks them to install.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.