How a Fake Recruiter Earns Your Trust
The most effective part of this attack isn’t the malware. It’s the profile.
Before any code changes hands, the attacker has to be believed. In the campaign LMG Security analyzed, that job fell to a LinkedIn persona named “Artem Vidloha” — an “Engineering Team Lead” focused on scalable systems and product engineering, based in the San Francisco Bay Area, with 500+ connections and a tidy professional “About” section.
The threat actor’s LinkedIn persona. It later displayed as “LinkedIn Member,” a sign the account was pulled after detection.
It wasn’t elaborate, and it didn’t need to be. As Tom Pohl notes, the profile only had to look plausible enough for a busy, hopeful job seeker to keep the conversation moving and treat the next step — a coding challenge — as normal.
Here’s what that thin layer of credibility actually accomplished:
- Role credibility — the engineering-leadership title matched what real technical peers look like.
- Domain fit — it signaled expertise in exactly the areas the target cared about.
- Low-cost legitimacy — minimal content was enough to start a trusted conversation.
- Hiring context — it primed the candidate to expect repos, code, and assessments, so nothing felt off.
The tell came later: the account flipped to display as “LinkedIn Member,” which usually means it was suspended or removed. By then, of course, the damage was already done.
For defenders, the lesson is that verification belongs in the hiring workflow. Candidates and recruiters on both sides should have a clear, low-friction way to confirm that a recruiter, a domain, a repository, and a coding challenge actually came from the organization they claim. Done well, verification removes friction for legitimate opportunities and adds it only for adversaries.
As the whitepaper puts it: the lure today becomes the exposure tomorrow. A convincing profile is cheap. Trust is the real payload — so teach your people, and your candidates, to verify before they engage.
Go deeper
This is part 2 of our series on the human supply chain. Read the full analysis in the LMG Security whitepaper at LMGsecurity.com (Resources), and hear Tom and Sherri on the Cyberside Chats episode, “Damaged Goods: When Your New Hire Is Already Compromised.”