A surge in online job scams is posing significant risks not only to individuals but also to corporate networks. Attackers are impersonating recruiters and luring victims with fake job offers, prompting them to download malicious software disguised as interview tools or application materials. According to a recent Google advisory, these scams are increasingly embedding remote access Trojans and info-stealers, which can compromise both personal and enterprise devices, leading to credential theft, fraud, and unauthorized access to corporate systems.
The Global Anti-Scam Alliance's 2025 report highlights the scale of the threat, with 57% of adults experiencing an online scam in the past year and 23% reporting financial losses. Security researchers warn that the consequences for victims include financial theft, identity fraud, and system compromise that enables further credential harvesting and infiltration of corporate networks. Enterprises are urged to address the risks posed by compromised personal devices and to implement robust fraud risk management strategies to mitigate these evolving threats.

Get the infrastructure and lures behind it.
1 event from the most recent confirmed update back to the earliest known activity.
GovInfoSecurity and BankInfoSecurity published coverage describing online job scams as an emerging threat that can create risks for corporate networks. No specific underlying incident, victim, or dated real-world event is provided in the references.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.