Jobs and income · Also called malicious coding test, fake technical interview, pre-employment test malware, fake video interview app
Fake job interview malware scam
A fake job interview malware scam is when a fake recruiter, often offering a well-paid tech or crypto role, asks you to install a custom video call app, run a script to fix your camera or audio, or complete a coding test. The file installs malware that can steal cryptocurrency or open a way into your employer's network.
How it works
- Attackers study targets on professional networking and job sites and pose as recruiters, well-known people, or fake recruiting firms with convincing websites.
- They offer an attractive job, often at a technology or cryptocurrency company, and build rapport over long conversations.
- They ask you to run code, such as a pre-employment test using unfamiliar packages or repositories, or a script to make the video call work.
- The code installs malware on your device, which can steal cryptocurrency or give the attackers access to company systems.
Red flags
- An unexpected job offer from a well-known technology or crypto firm offers unusually high pay without negotiation.
- You are asked to complete a pre-employment test or debugging exercise that runs unfamiliar packages, scripts, or code repositories.
- The interviewer insists on custom software for a video call, or asks you to run a script to make your camera or audio work.
- You are asked to move the conversation to a different messaging app.
If you are targeted
- Stop contact and do not run any more files or commands from the interviewer.
- Disconnect the device from the internet but leave it powered on, and if it is a work device, tell your employer's security team at once.
- From a different, clean device, change passwords for accounts you used on the affected device.
- Report it. Our Report a scam page lists where to report in your country, such as ic3.gov and ReportFraud.ftc.gov in the US.
- Keep screenshots of the messages, usernames, and files so you can share them with investigators.
Prevention
For individuals
- Verify a recruiter's identity through a separate channel, such as the company's own careers page or a live video call on a different app.
- Never run a coding test on a work laptop; if a test needs code to run, use a virtual machine on a device not connected to your employer.
- Do not keep crypto wallet passwords, seed phrases, or private keys on internet-connected devices.
For organisations
- Block company devices from running unapproved programs, and tell staff never to take pre-employment tests on company equipment.
- Require several approvals, from separate unconnected devices or networks, before any movement of company funds or crypto assets.
- Limit access to code repositories and sensitive network documents to the staff who need them.
By the numbers
Figures are for the reporting category this scam falls under, not this scam alone.
| Malware losses reported to the FBI IC3 in 2025 | $19.4M | US, 2025, FBI IC3 |
Real cases
No documented case in the atlas yet. New cases are added as they are sourced.
Delivered through: Spear phishing, Fake apps
How official datasets classify it
- FBI IC3
- Malware
- MITRE ATT&CK
- T1566.003, T1204.002
Questions
- Is it safe to run a coding test a recruiter sends me?
- Treat it with caution. The FBI warns that fake recruiters use pre-employment tests with unfamiliar packages to install malware. Never run one on a work device, and use an isolated virtual machine if you must.
- I ran a script from a job interview. What should I do?
- Disconnect the device from the internet but leave it on, tell your employer's security team if it is a work device, change your passwords from a clean device, and report it.
Related scams
- Developer-targeted lures (fake job tests and malicious packages)
- North Korean fake IT workers
- Fake recruiter and hiring scam
- Crypto wallet drainer