{"id":12628,"date":"2018-06-20T09:10:02","date_gmt":"2018-06-20T17:10:02","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2018\/06\/20\/news-6396\/"},"modified":"2018-06-20T09:10:02","modified_gmt":"2018-06-20T17:10:02","slug":"news-6396","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2018\/06\/20\/news-6396\/","title":{"rendered":"PSA: Recruitment portals and job sites at risk"},"content":{"rendered":"<p><strong>Credit to Author: Malwarebytes Labs| Date: Wed, 20 Jun 2018 16:00:00 +0000<\/strong><\/p>\n<p>Readers of Malwarebytes Labs aren&#8217;t new to the social engineering tactics of malcontents to get users to respond to fake job offers via email.<\/p>\n<p>In 2014, we <a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2014\/02\/job-application-mail-shows-great-potential-for-installing-something\/\" target=\"_blank\" rel=\"noopener\">wrote<\/a> about spam claiming to be from the recipient&#8217;s supposed work application to a &#8220;Career Services Department,&#8221; only to be redirected to a site where a potentially unwanted program (in the guise of a video player) was on standby for download. Then in 2016, we <a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2016\/04\/spam-serves-up-health-service-legal-disclaimers-and-job-offer\/\" target=\"_blank\" rel=\"noopener\">focused<\/a> on a spam claiming to originate from someone in the NHS, the UK&#8217;s public health service provider, only to do a complete 180 by welcoming\u00a0email respondents with a job offer to sell light fixtures.<\/p>\n<p>As bizarre and downright obvious as the above examples are to some, they&#8217;re not for others. This is why we generally advise continuous education and security awareness in detecting <a href=\"https:\/\/blog.malwarebytes.com\/101\/2018\/06\/five-easy-ways-to-recognize-and-dispose-of-malicious-emails\/\" target=\"_blank\" rel=\"noopener\">red flags in all emails<\/a>\u2014and that includes from potential future employers. The same can be said to those in the business of recruitment and job search platforms.<\/p>\n<h3>Recruitment portals give bad guys access to vulnerable people<\/h3>\n<p>According to recent research from our friends at Flashpoint, threats targeting recruitment portals and job listing sites are <a href=\"https:\/\/www.flashpoint-intel.com\/blog\/targeting-job-recruitment-portals\/\" target=\"_blank\" rel=\"noopener\">on the rise<\/a>. And the criminals aren&#8217;t just after job seekers&#8217; personal information anymore. Flashpoint analysts have found that there is interest in the black market around compromised accounts belonging to job recruitment portals, whether they were from employees or from the businesses these platforms are working with.<\/p>\n<p>Criminals prefer access to business accounts so they can create attractive fake job offers under the names of legitimate companies (which would be awfully difficult to avoid clicking on if you&#8217;re in the process of actively looking for a job). Not only can they phish unsuspecting users for their PII, but they can also drop other malware payloads via malicious links or attachments to compromise systems.<\/p>\n<p>In addition, recruitment portals can inadvertently become a platform for recruiting individuals who would become <a href=\"https:\/\/blog.malwarebytes.com\/threat-analysis\/2013\/10\/money-mules-if-it-looks-too-good-to-be-true\/\" target=\"_blank\" rel=\"noopener\">money mules<\/a>\u00a0or part of other money laundering schemes without their knowledge. Unfortunately,\u00a0<a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/12\/children-and-young-adults-the-next-generation-money-mules\/\" target=\"_blank\" rel=\"noopener\">children and young adults have already been exposed<\/a> to this type of fraud by other means. Adding job recruitment sites to the list only sweetens the highly vulnerable pot.<\/p>\n<h3>Recruitment professionals are in the crosshairs, too<\/h3>\n<p>Employees of recruitment portals themselves can also fall victim to attacks. &#8220;Malicious documents in the guise of a PDF\u2019d application can also slip past lax or non-existent scanning tools and target the recruitment portal directly, or enable an attacker access to data stored on the portal and expose applicants to identity theft,&#8221; wrote David Shear, Flashpoint analyst, in a blog post. Phishing campaigns could be highly effective against recruitment professionals, as they regularly receive an influx of email and attachments from unknown recipients<\/p>\n<p>In <a href=\"https:\/\/www.infosecurity-magazine.com\/news\/uptick-in-threats-to-job-sites\/\" target=\"_blank\" rel=\"noopener\">an interview<\/a> with Infosecurity Magazine, Shear said that criminals may likely gravitate toward enterprise business accounts from these portals as they are not only profitable but also allow for threat actors to remain undetected for long periods of time because of the inherent complexity of large organizations and poor communication.<\/p>\n<p>Flashpoint has provided <a href=\"https:\/\/www.flashpoint-intel.com\/blog\/targeting-job-recruitment-portals\/\" target=\"_blank\" rel=\"noopener\">recommendations and mitigation steps<\/a> in their blog post that recruiters must consider to address this problem.<\/p>\n<p>Stay safe, everyone!<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/06\/psa-recruitment-portals-and-job-sites-at-risk\/\">PSA: Recruitment portals and job sites at risk<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/06\/psa-recruitment-portals-and-job-sites-at-risk\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Malwarebytes Labs| Date: Wed, 20 Jun 2018 16:00:00 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/06\/psa-recruitment-portals-and-job-sites-at-risk\/' title='PSA: Recruitment portals and job sites at risk'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/shutterstock_657215752.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>We&#8217;ve warned job seekers to be wary of phishing attacks, and we&#8217;re now doing the same for recruitment professionals: Beware of your recruitment portals, as they may play host to a lot of bad apples who\u2014trust us\u2014you wouldn&#8217;t want to hire out anywhere. <\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/\" rel=\"category tag\">Cybercrime<\/a><\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/social-engineering-cybercrime\/\" rel=\"category tag\">Social engineering<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/job-site-vulnerabilities\/\" rel=\"tag\">job site vulnerabilities<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/recruitment-portal-flaws\/\" rel=\"tag\">recruitment portal flaws<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/06\/psa-recruitment-portals-and-job-sites-at-risk\/' title='PSA: Recruitment portals and job sites at risk'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/06\/psa-recruitment-portals-and-job-sites-at-risk\/\">PSA: Recruitment portals and job sites at risk<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[4503,18799,18800,10510],"class_list":["post-12628","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-cybercrime","tag-job-site-vulnerabilities","tag-recruitment-portal-flaws","tag-social-engineering"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/12628","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=12628"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/12628\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=12628"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=12628"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=12628"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}