Social Engineering Attacks Using Technical Job Interviews: Real-Life Case Analysis and AI-Assisted Mitigation Proposals

dc.contributor.authorMateo Sanguino, Tomás Jesús
dc.date.accessioned2026-01-28T12:47:03Z
dc.date.available2026-01-28T12:47:03Z
dc.date.issued2025
dc.description.abstractTechnical job interviews have become a vulnerable environment for social engineering attacks, particularly when they involve direct interaction with malicious code. In this context, the present manuscript investigates an exploratory case study, aiming to provide an in-depth analysis of a single incident rather than seeking to generalize statistical evidence. The study examines a real-world covert attack conducted through a simulated interview, identifying the technical and psychological elements that contribute to its effectiveness, assessing the performance of artificial intelligence (AI) assistants in early detection and proposing mitigation strategies. To this end, a methodology was implemented that combines discursive reconstruction of the attack, code exploitation and forensic analysis. The experimental phase, primarily focused on evaluating 10 large language models (LLMs) against a fragment of obfuscated code, reveals that the malware initially evaded detection by 62 antivirus engines, while assistants such as GPT 5.1, Grok 4.1 and Claude Sonnet 4.5 successfully identified malicious patterns and suggested operational countermeasures. The discussion highlights how the apparent legitimacy of platforms like LinkedIn, Calendly and Bitbucket, along with time pressure and technical familiarity, act as catalysts for deception. Based on these findings, the study suggests that LLMs may play a role in the early detection of threats, offering a potentially valuable avenue to enhance security in technical recruitment processes by enabling the timely identification of malicious behavior. To the best of available knowledge, this represents the first academically documented case of its kind analyzed from an interdisciplinary perspective.
dc.description.departmentIngeniería Electrónica, de Sistemas Informáticos y Automática
dc.identifier.citationMateo Sanguino, T. J. (2026). Social Engineering Attacks Using Technical Job Interviews: Real-Life Case Analysis and AI-Assisted Mitigation Proposals. Information, 17(1), 98. https://doi.org/10.3390/info17010098
dc.identifier.doi10.3390/info17010098
dc.identifier.issn2078-2489 (electrónico)
dc.identifier.urihttps://hdl.handle.net/10272/27811
dc.language.isoeng
dc.publisherMDPI
dc.rightsAttribution 4.0 Internationalen
dc.rights.accessRightsopen access
dc.rights.urihttp://creativecommons.org/licenses/by/4.0/
dc.subject.otherSocial engineering
dc.subject.otherTechnical job interviews
dc.subject.otherMalicious code detection
dc.subject.otherObfuscated JavaScript
dc.subject.otherAI-assisted cybersecurity
dc.subject.otherCrypto wallet compromise
dc.subject.otherThreat mitigation strategies
dc.subject.otherRemote code execution
dc.subject.unesco1203 Ciencia de Los Ordenadores
dc.subject.unesco1203.04 Inteligencia Artificial
dc.titleSocial Engineering Attacks Using Technical Job Interviews: Real-Life Case Analysis and AI-Assisted Mitigation Proposals
dc.typejournal article
dc.type.hasVersionVoR
dspace.entity.typePublication
relation.isAuthorOfPublicationd331bf94-eca1-430b-91dd-10623f4cbe95
relation.isAuthorOfPublication.latestForDiscoveryd331bf94-eca1-430b-91dd-10623f4cbe95

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
information-17-00098.pdf
Size:
3.51 MB
Format:
Adobe Portable Document Format

Collections