NewsCryptoRelay Malware Uses Fake AI Meeting App to Target Crypto Wallets of Web3 Job Applicants

Relay Malware Uses Fake AI Meeting App to Target Crypto Wallets of Web3 Job Applicants

Author: CoinWy·

Key Takeaways

  • The Relay malware strain is distributed through a fake AI meeting application disguised as interview software targeting Web3 job seekers.
  • Blockchain security firm SlowMist published the threat intelligence report documenting this information-stealing campaign.
  • The attack relies on social engineering by embedding malicious software within a recruitment workflow, making it appear more legitimate than typical phishing attempts.
  • Web3 job applicants are especially vulnerable because many hold cryptocurrency and regularly interact with wallets as part of their professional activities.
  • Security experts recommend verifying software through official websites, confirming recruiter identities via established company channels, and using separate devices for sensitive wallet operations.
Relay Malware Uses Fake AI Meeting App to Target Crypto Wallets of Web3 Job Applicants

A malware strain known as Relay is reportedly using a fake AI meeting application to target the cryptocurrency wallets of Web3 job applicants, according to a SlowMist threat intelligence report. SlowMist is a blockchain security firm that regularly publishes analyses of phishing and wallet-draining campaigns affecting the crypto ecosystem.

Security researchers describe Relay as an information-stealing tool delivered through what appears to be interview software presented to job seekers. The campaign specifically targets individuals pursuing roles in the Web3 sector.

Social Engineering at the Core

The attack relies primarily on social engineering rather than a technical exploit. By disguising the malware as a meeting or interview tool that a candidate is instructed to install, attackers exploit the trust inherent in a standard hiring workflow. The ultimate objective is to gain access to the crypto wallets of those who download the application.

The fake AI meeting app serves as the entry point for the entire attack chain. In a Web3 hiring context, candidates are frequently asked to download interview or meeting software — a routine request that makes the instruction difficult to question. The rapid proliferation of legitimate AI-powered meeting and transcription tools in recent years further increases the plausibility of such a request, as organizations across industries have adopted new video-conferencing and AI-assisted platforms.

Because the targets are job applicants, the malware is embedded within a recruitment sequence rather than arriving as an unsolicited link. Similar recruitment-themed lures aimed at Web3 developers have been documented by security reporters covering fraudulent recruiter campaigns targeting the sector. Recruitment-based social engineering has also been reported in the broader technology industry, where fake interview processes have been used to deliver malware to software engineers. This framing gives the download a level of legitimacy that conventional phishing attempts typically lack.

From there, the reported goal is the applicant's crypto wallet. The specific execution steps and wallet-draining mechanics are not detailed in the available SlowMist research, and therefore are not stated here as confirmed fact.

Implications for Web3 Hiring and Wallet Security

Web3 job applicants represent a particularly attractive target group because many already hold cryptocurrency and regularly interact with wallets as part of their professional activities. This overlap between the candidate pool and active wallet users makes them highly appealing to attackers.

Wallet-focused attacks carry more severe consequences than routine credential phishing. Once wallet access is compromised, digital assets can be transferred directly — a risk pattern also seen in cases such as the lawsuit over a fake iPhone wallet app tied to an alleged Bitcoin theft. Unlike traditional banking transactions, many cryptocurrency transfers cannot be reversed, which means that successful wallet compromises often result in permanent loss of funds.

The combination of fake AI tooling and recruitment-oriented language indicates that attackers are adapting their lures to current technology and hiring trends. For both candidates and hiring teams operating in the crypto space, the practical guidance is to exercise caution when asked to install any interview software by an unverified recruiter. Verifying software through official websites, using separate devices for sensitive wallet operations, and confirming recruiter identities through established company channels are among the standard precautionary measures recommended by security practitioners.