Friday, September 4


Cyber-security researcher Charlie Kelly from Have I Been Squatted carried out an analysis of how the attack worked and said the new wave of recruitment scams were hard to spot.

“This wasn’t a badly written email with a suspicious attachment – this person was walked through what looked like a real job interview, on real Google pages, behind a real Google login, and the software they were asked to install was digitally signed like any legitimate app.”

The case comes as others have reported similar attacks through the job listing platform Indeed, which put out advice in July about avoiding scams, external.

Criminals are using the pressure and excitement of job interviews to lure people into downloading booby-trapped mobile applications like a fake Indeed Interview app or one called MyInterview.

According to cyber-security company Malwarebytes, the fake recruiters use lures such as: “Complete your interview by installing the Indeed app” or “salary agreement available after app installation”.

Once downloaded the malicious apps allow hackers to access private data for extortion or to use in financial attacks.

“Interviewing through Indeed’s platform happens entirely in a browser and never requires downloading a special app,” the company recently posted online.

“Any message asking a job seeker to download an app to participate in an interview is not legitimate.”



Source link

Share.
Leave A Reply

Exit mobile version