DEV Community

Cover image for The Podcast Invitation: Luring People With Hint of Media Visbility
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

The Podcast Invitation: Luring People With Hint of Media Visbility

Summary

Unsolicited podcast-guest invitations are a highly effective social engineering lure: they flatter targets and lead to live video calls where attackers can deliver malware, phishing logins, or remote-control requests, gather reconnaissance, and record voice and face samples for deepfakes. North Korea-linked actors used this method in the 2025 ELUSIVE COMET campaign to steal crypto assets.

Take Action:

Treat any unexpected podcast invitation as a sales pitch or attack until proven otherwise: verify the show and its past guests yourself (not through links in the email), and ask for topics by email instead of joining "intro" or "tech check" calls. Never install software, open attachments, log in through their links, or accept remote control or screen-sharing requests. Assume everything you say on the call is public, so keep details about your tools, processes and issues out of it.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)