Fake Job Video Calls Target Rust Developers

Security Week Feed · High sophistication
Last updated September 21, 2026

The Rust project warned of an active social engineering campaign targeting Rust team members and popular crate maintainers. Attackers pose as recruiters or contractors, lure developers into video calls, then trick them into installing software or running pasted code to steal credentials and publish malicious packages.

Key findings

  • Attackers are targeting Rust-lang team members and owners of popular crates to hijack developer credentials and publish malicious packages.
  • The lure is a video call framed as a job offer or contract opportunity.
  • On the call, victims are tricked into installing software (claimed to be a missing audio codec) or running malicious code copied to their clipboard.
  • Attackers create fake companies with LinkedIn pages to look legitimate.
  • The campaign resembles earlier incidents, including the August compromise of the arrayref crate where an account takeover led to malicious crates being published.
  • The Rust team notes North Korea is known for this style of operation but did not attribute the current activity to a specific actor.

Who’s being targeted

  • Commonly targeted roles: Software Developers, Open Source Maintainers, Engineering Managers, DevOps / Release Engineering, Security / Incident Response.
  • Affected industries: Software development, Open source ecosystems, Developer tooling / package registries.
  • Attack channels: linkedin, vishing.
  • Impersonated: New company recruiter (fake company with LinkedIn presence), Interviewer for a supposed Rust job/contract.

Awareness takeaways

  • Treat unsolicited recruiting/contract outreach as a potential scam, verify the company and recruiter through trusted, independent channels.
  • Never install software or run commands during an interview/call to ‘fix audio’ or ‘validate’ your setup; stop and verify with your security process.
  • Use trusted meeting platforms, and preferably meetings you create yourself, when speaking with new external contacts.
  • Protect developer and registry accounts with MFA and routinely check for unusual logins to reduce account-takeover and supply-chain risk.

Red flags to watch for

  • Unsolicited job/contract approach pushing a rushed video call
  • Pressure to install software during an interview to ‘fix audio’
  • Company looks new or thin but has a polished LinkedIn page
  • Any interviewer asking you to run commands or paste code during a call
  • Clipboard-based instructions that bypass normal review (no written context, no repo link)
  • Unsolicited contact with unusual technical requests unrelated to interviewing
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get a LinkedIn message: “We’re hiring for a Rust contract role, can you jump on a quick video call?” Sounds great, right? Rust-lang warned: attackers are posing as recruiters, jumping on video calls, then telling crate maintainers to install a ‘missing audio codec’ or paste and run a command they drop into your clipboard. The goal is to hijack Rust developer credentials and push malicious crates, just like the earlier arrayref compromise. These fake companies even spin up convincing LinkedIn pages that pass a quick glance. If any interviewer asks you to install software or run commands during the call, stop immediately, end the call and report it to security before you touch your terminal.

Categories

Similar attacks

Fake Rust Job Interviews Push Malware on Devs

Fake Rust Job Interviews Push Malware on Devs

The Rust Project warned that attackers are approaching Rust contributors and crate maintainers with believable recruiter outreach and “company” profiles, then using interview video calls to trick targets into installing malware or running commands. The activity is described as similar to North…

September 21, 2026
Teams Helpdesk Vishing Pushes Remote Control Tools

Teams Helpdesk Vishing Pushes Remote Control Tools

Researchers observed a coordinated social-engineering operation (“Spring Ring”) where attackers used external Microsoft Teams accounts to pose as internal IT help desk staff and start voice calls. Victims were pressured to install remote-control tools (like Quick Assist or other RMM software) or…

August 31, 2026
Fake Web3 Job Interviews Push “ClickFix” Malware

Fake Web3 Job Interviews Push “ClickFix” Malware

Researchers say a North Korea-aligned group is targeting Web3 and crypto professionals with fake recruiter outreach and “mandatory” online skill tests. During the test, victims are tricked into copying a terminal command to “fix” a camera/mic error, which installs remote-access malware and can lead…

July 21, 2026
Fake Recruiters & Cloud Email Fuel New Phishing

Fake Recruiters & Cloud Email Fuel New Phishing

This roundup describes real-world social engineering where attackers impersonate recruiters on LinkedIn and lure developers into running “coding tests” that install malware. It also outlines active phishing campaigns that abuse trusted cloud services (Google, AWS, Azure, Cloudflare) to send…

September 2, 2026
AI Voice “Apple Support” Phishing + Fake IT Helpdesk

AI Voice “Apple Support” Phishing + Fake IT Helpdesk

This news roundup describes real social-engineering operations where attackers impersonate trusted support teams to trick people into giving up secrets. One campaign uses email/SMS/WhatsApp plus AI voice calls pretending to be Apple Support to steal iPhone passcodes, while another uses phishing…

August 27, 2026
DEF CON Attendees Hit With Fake CoinDesk DMs

DEF CON Attendees Hit With Fake CoinDesk DMs

After Black Hat/DEF CON, cybercriminals allegedly targeted conference attendees by impersonating a CoinDesk executive over X direct messages. Victims were pushed into a realistic workflow using Google Docs and a fake Dropbox DocSend installer to trick them into running malware on macOS or Windows.

August 21, 2026