CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
← Back to Daily brief 2026-06-10
NOTABLEupdatedNATOA2threat

NCSC-CH Week 23: three job-seeker scams, a fake interview login, reshipping identity theft and LinkedIn-to-GitHub infostealer delivery

Analysis

NCSC Switzerland's Week 23 review (9 June) walks through three reported cases aimed at job seekers (NCSC-CH, 2026-06-09). In the first, a job seeker was offered a phone-interview slot to confirm through a Google Calendar entry, and the confirmation opened a counterfeit Google login that sent the entered credentials to the scammers. In the second, an ad for a "Swiss social welfare" work-from-home packing job moved to WhatsApp and asked for photos of the passport, identity card, driving licence and home address. Such documents are used to order high-value goods in the victim's name, and the job itself is parcel reshipping that hides criminal proceeds. In the third, a recruiter on LinkedIn, in one case writing from a compromised but genuine-looking profile, offered a technical position and, as part of a technical interview, asked the candidate to download a private GitHub repository and complete a small programming task in it. Running the commands installed an infostealer that reads crypto wallets, stored login credentials and browser cookies. NCSC notes that attackers systematically exploit applicants' willingness to react quickly and engage with unfamiliar procedures.

Why it matters to us: the LinkedIn-to-GitHub chain is a credible vector into corporate endpoints through employees in job-search mode and HR or talent teams handling external candidate code. Detection concept, by inference from the mechanism: a repository clone or GitHub download followed within minutes by script execution from the freshly cloned path (process-creation telemetry, for example Sysmon event 1 with git or an interpreter as the parent).

Updates1

Correction

NCSC Switzerland's Week 23 review presents three reported cases, not a coordinated campaign (NCSC-CH, 2026-06-09). The fake interview was a phone-interview slot confirmed through a Google Calendar entry, which opened a counterfeit Google login. The recruiter case was a technical interview in which the candidate downloaded a private GitHub repository and ran a small programming task, and running its commands installed the infostealer. The analysis had described interview-confirmation emails from Swiss employers, an onboarding or technical-assessment repository and PowerShell, which the page does not say, and it now follows the page. The citation now points at the page's new address on bacs.admin.ch, after the old ncsc.admin.ch page went dead.

Sources1

Revision history

  1. Published 2026-06-10-c84347b2
  2. Correction 2026-09-30T0634Z-audit

    NCSC presents three reported cases rather than a coordinated campaign, and none of the Swiss-employer emails, onboarding repository or PowerShell the analysis described, so the title, summary and analysis now follow the page. The citation follows the page to its new address on bacs.admin.ch.

    Changed: sources techniques classification title headline summary sectors body

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.