This latest LinkedIn scam sends fake job offers to lure victims in

LinkedIn
(Image credit: Shutterstock)

Users on LinkedIn have been warned about another scam that is targeting jobseekers on the social media platform.

A report from security firm eSentire has discovereda group of scam artists known as “Golden Chicken” that sends out fake job offers in an effort to infect victims with a sophisticated backdoor Trojan.

The scammers are apparently backed by advanced threat groups including FIN6, Cobalt Group and Evilnum as they look to attack those looking for a new job on LinkedIn.

Fake offers

eSentire research found that the simplest way to identify a fake job offer is to look at the file name and file type that’s been sent across to you. 

A message containing a job offer in a “Zip” file format can be the first signal, with the company also suggesting looking at the file name. It notes that for example, one file claiming to advertise a job listed as "Senior Account Executive—International Freight" came with a malicious zip file titled Senior Account Executive—International Freight position - with the "position” added at the end a major giveaway.

This compressed file contains automatically installable stealthy trojans called “more eggs” that get installed as soon as the file is unzipped, offering unrestricted access of users’ devices to the scammers.

Once these hackers get access to the device, it offers a backdoor to the scam artists to install malware of their choice including Ransomware, credential stealers, banking malware or even simply to steal user data silently.

What makes this attack lethal is the fact that this malware runs in a stealth mode and uses normal Windows processes to run hence there are chances that the anti-virus program on your computer might not even notice it.

The news comes shortly after the personal data of around 500 million LinkedIn users was found being sold on a popular hacking forum.

The hoard included LinkedIn IDs, full names, email addresses, phone numbers, genders, links to LinkedIn profiles, links to other social media profiles, and professional titles, and other work-related data - although no passwords or payment data appear to have been affected. 

TOPICS
Jitendra Soni

Jitendra has been working in the Internet Industry for the last 7 years now and has written about a wide range of topics including gadgets, smartphones, reviews, games, software, apps, deep tech, AI, and consumer electronics.  

Read more
Hacker silhouette working on a laptop with North Korean flag on the background
North Korean hackers are targeting LinkedIn jobseekers with new malware - here's how to stay safe
linkedin
Watch out - that LinkedIn email could be a fake, laden with malware
A digital representation of a lock
Looking for a new job? Watch out you don't fall for this new malware scam
Red padlock open on electric circuits network dark red background
CrowdStrike warns of fake job offer scam that is actually just malware
Hacker silhouette working on a laptop with North Korean flag on the background
North Korean Lazarus hackers are targeting nuclear workers
Representational image of a cybercriminal
Criminals are spreading malware disguised as DeepSeek AI
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras