AI-Generated Fake nVidia Employee LinkedIn Profiles Surface in Hiring Scams

Cybersecurity researchers have uncovered a sophisticated campaign using AI-generated LinkedIn profiles impersonating nVidia employees to lure job seekers into downloading malware, according to a report from Silent Push researchers published Thursday.

The campaign, dubbed “DevPopper,” creates convincing fake LinkedIn profiles complete with AI-generated headshots, realistic work histories, and fabricated connections at nVidia. These profiles reach out to software developers and engineers with job offers, directing them to GitHub repositories or malicious websites hosting malware designed to steal credentials, cryptocurrency wallets, and sensitive development data.

“The level of sophistication in these AI-generated personas is unprecedented,” said Silent Push researcher Scott N. in the report. “The profiles have years of fabricated work history, realistic connections, and even AI-generated profile photos that pass casual inspection.”

Victims who engage with the fake recruiters are directed to cloned GitHub repositories containing malicious code disguised as coding challenges or technical assessments. Once executed, the malware — identified as a variant of the BeaverTail information stealer — exfiltrates browser credentials, cryptocurrency wallet data, and SSH keys from development environments.

Silent Push researchers identified over 300 fake LinkedIn profiles tied to the campaign, with the earliest dating back to late 2023. The campaign appears to target developers in the AI, machine learning, and cryptocurrency sectors specifically.

“We are aware of fraudulent activity using our brand and are working with LinkedIn and law enforcement to address it,” an nVidia spokesperson told The Coolest. “We never recruit through unsolicited direct messages or ask candidates to download code from personal repositories.”

LinkedIn told The Coolest it has removed the identified profiles and is improving its detection systems for AI-generated content. The platform removed over 32 million fake accounts in the second half of 2023 alone, according to its latest transparency report.

Security researchers advise developers to verify recruiters through official company channels, avoid downloading code from personal repositories, and use hardware security keys for GitHub and cryptocurrency accounts. Silent Push has published indicators of compromise, including malicious domains and GitHub repositories, to help organizations block the threat.

Source: Silent Push Research Blog