Live data from Hacker News

A fake job offer took down Axie Infinity

theblock.co

1–10 of 364 posts

Re: A fake job offer took down Axie Infinity

#4
Two points to highlight from this article:

1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this.

2. I wish there were more information about what the vulnerability was in the PDF in the first place. I think a lot of people would be wary of downloading a PDF from a stranger, but not from someone who you had multiple interview rounds with and who offered you a job.

Re: A fake job offer took down Axie Infinity

#7

They say that a worker downloading (and presumably viewing) a PDF (fake job offer) allowed spyware in. Which PDF viewer was exploited?

im guessing it was the ol' ".pdf.exe" trick.

That trick doesn't work anymore for any reasonably modern email client.

Re: A fake job offer took down Axie Infinity

#8
Curious if anyone has been able to find technical details of how this attack works/worked. I'm under the impression most PDF viewers would prevent this sort of attack (e.g. opening a PDF in your browser should sandbox it to the browsing context), but really keen to know what PDF viewer / OS was used by the dev.

Re: A fake job offer took down Axie Infinity

#9

Earlier quoted context omitted.

im guessing it was the ol' ".pdf.exe" trick.

That trick doesn't work anymore for any reasonably modern email client.

That's when you remind him that your boss needs to get this role filled by the end of the week so if you don't get a response by tomorrow you'll have no choice but to offer the job to another candidate.
Post reply on HN