Hackers are now sending fake LinkedIn job offers to steal user data

linkedin
(Image credit: Shutterstock / Ink Drop)

Millions of people are active on LinkedIn looking for a job opportunity after the impact of Covid-19. These people are either in search of a job after they lost their job thanks to the pandemic or they're looking to switch to a better job.

However, it is not just the job seekers and employers who’re active on the professional network, Hackers are also active on LinkedIn. These interlopers are coming up with innovative ways to lure unassuming candidates into sharing their personal details or even give unrestricted access to their computers to these crooks.

According to a report, a group of scam artists that are known as “Golden Chicken” who are backed by advanced threat groups like FIN6, Cobalt Group and Evilnum are behind this new age attack that targets job seekers on LinkedIn.

How to identify fake job offers on LinkedIn? 

As per eSentire, the simplest way to identify a fake job offer is to look at the file name and file type that’s been sent across to you. A message containing a job offer in a “Zip” file format can be the first signal. 

The research team then suggests looking at the file name and states that the “LinkedIn member’s job is listed as Senior Account Executive—International Freight the malicious zip file would be titled Senior Account Executive—International Freight position (note the “position” added to the end).”

Hence, the word “position” at the end is the biggest giveaway that this file could be a harmful trojan and need to be done away with.

What happens if someone opens it? 

According to the Threat Response Unit of eSentire, a leading cybersecurity solutions provider, hackers are sending fake job offers in a zip format to job seekers. This compressed file contains automatically installable stealthy trojans called “more eggs” that get installed as soon as the file is unzipped, offering unrestricted access of users’ devices to the scammers.

Once these hackers get access to the device, it offers a backdoor to the scam artists to install malware of their choice including Ransomware, credential stealers, banking malware or even simply to steal user data silently.

What makes this attack lethal is the fact that this malware runs in a stealth mode and uses normal Windows processes to run hence there are chances that the anti-virus program on your computer might not even pick it.

The best way to avoid this attack is to be watchful of the files that you download on your computer. Make sure it has come from an authentic source and in case it’s a zip file, be extra cautious of the obvious hints like the name etc. In regular scenarios, you’re not going to receive a job offer for a position that you’ve never applied for.

Get up close with consumer tech news that you can use, latest reviews and buying guides. Follow TechRadar India on TwitterFacebook and Instagram!

TOPICS
Jitendra Soni

Jitendra has been working in the Internet Industry for the last 7 years now and has written about a wide range of topics including gadgets, smartphones, reviews, games, software, apps, deep tech, AI, and consumer electronics.  

Read more
Hacker silhouette working on a laptop with North Korean flag on the background
North Korean hackers are targeting LinkedIn jobseekers with new malware - here's how to stay safe
linkedin
Watch out - that LinkedIn email could be a fake, laden with malware
Representational image depecting cybersecurity protection
Fake video conferencing apps are targeting Web3 workers to steal their data
Red padlock open on electric circuits network dark red background
CrowdStrike warns of fake job offer scam that is actually just malware
A digital representation of a lock
Looking for a new job? Watch out you don't fall for this new malware scam
Security padlock and circuit board to protect data
Foh&Boh data leak leaves millions of CVs exposed - KFS, Taco Bell, Nordstrom applicants at risk
Latest in Cyber Crime
A person scanning a QR code on a smartphone
Quishing is the new QR code scam you need to watch out for – here's how to stay safe
Ransomware on the rise: how small and medium-sized businesses can achieve cyber resilience during turbulent times
Ransomware on the rise: how small and medium-sized businesses can achieve cyber resilience during turbulent times
Text Phishing Scams
Do not fall for this dangerous Amazon shopping scam
Cyber-security
Safeguarding against next-gen cyber risks
The North Face jacket
Thousands of North Face customers accounts hacked, personal data stolen
Smartphone hacked with data flow in the background
9 signs your phone has been hacked
Latest in News
WhatsApp
WhatsApp just made its AI impossible to avoid – but at least you can turn it off
ChatGPT vs Gemini comparison
I compared GPT-4.5 to Gemini 2.0 Flash and the results surprised me
Apple iPhone 16 Plus
Apple officially delays the AI-infused Siri and admits, ‘It’s going to take us longer than we thought’
The Meta Quest Pro on its charging pad on a desk, in front of a window with the curtain closed
Samsung, Apple and Meta want to use OLED in their next VR headsets – but only Meta has a plan to make it cheap
AMD Ryzen 9000 3D chips
AMD officially announces price and release date for Ryzen 9 9900X3D and 9950X3D processors
Google Pixel 9
There's something strange going on with Google Pixel phone vibrations after the latest update