Services

9

IT Managed Services

9

Compliance

9

Cybersecurity

9

Cloud & Network

9

Backup & Disaster Recovery

9

Business Communications

9

Web Design

9

Web Services

Expertise

9

Manufacturing

IT & Compliance support tailored for Manufacturers

9

Healthcare

IT & HIPAA support for Healthcare Practices

9

Public Sector

Specialized technology solutions & support for the particular needs of Government and other Public Sector entities

About

9

About Us

9

Legacy Brands

9

CloudTotally

9

River City Digital

9

MyRealTown

9

SilverGear

9

Testimonials

Resources

9

Hey Soteria blog

9

Events

9

Videos

9

Books

9

Referral Program

9

Partner Resources

9

Bill Pay

Contact

9

1815 E Central • Wichita, KS • 67214

Scam of the Month: Fake Applicants, Fake Jobs: A Two-Sided Coin

Scam of the Month

June 12, 2024

A Person Tossing a Coin

Scam of the Month

A favorite feature of our Monthly Newsletter, now on the Blog!

Malware disguised as resumés, applicant pools filled with bots, fake job offers that serve malware, or steal personal information…

It’s rough out there, for HR and job hunters alike.

I read this article from Hacker News today, about a phishing attack that was recently uncovered, although scams like it have been around for years.  In this scam, the threat actors apply for jobs and send a link to download a resumé, which will also download a bunch of malware.

 

This sort of scam has a flip side, too:  as I was writing this blog, a story broke about a new Windows malware named ‘Warmcookie’, which is distributed through personalized emails containing fake job offers. Clicking the email leads to a legitimate-looking landing page, where you are asked to download the job description. Unfortunately, clicking that will download Warmcookie insted.  Warmcookie installs a backdoor into infected machines, “capable of extensive machine fingerprinting, screenshot capturing, and the deployment of additional payloads.”  intended to surveil and breach corporate networks. Unfortunately, this isn’t an exactly new idea, either: in 2023, a long-running campaign by a North Korean threat group was discovered, called “Operation Dream Job” that targeted defense and nuclear engineers with fake job opportunities, but beginning the ” job interview” would download a payload of malware instead. 

 

It got me thinking about all the other instances I’ve seen recently of job related scams – (there’s so many variants, I might need to make this a whole series of blog posts!) and it almost makes you wonder how anyone is actually getting hired at all.

 

Thankfully, none of them are as terrifying as this report, of thousands of people being lured to Southeast Asia with the promise of jobs, only to be kidnapped, trafficked, tortured, and forced into running online scams in inhuman labor camps.

 

So what is the takeaway?  How do we protect ourselves and our companies?

  • If a job offer comes seemingly out of the blue, or a new job posting seems too good to be true, it probably is.  If you think it is legitimate, do your due diligence and thoroughly investigate the company and the people hiring before replying to the offer or post.
  • On the HR side, never go to someone’s webpage to download their resumé. Ask applicants to submit a resumé to you, and be very careful about what file types you accept.  One way to filter it automatically would be to accept resumés through an online file uploader, set to only accept txt, docx, and pdf files.
  • If you suspect you are the victim of a scam, report it! Report it to your local police, and the FBI’s Internet Crime Complaint Center (IC3) at: https://www.ic3.gov/Home/ComplaintChoice

This post, like all our posts, is 100% written by a human.

Like What You See? Sign Up For Our Newsletter!

News, Events, Tips from the Techs and more, delivered to your email once a month. Absolutely No Spam!

Newsletter Signup

Related Posts

What else is happening in

The Blog