Cybercriminals are increasingly targeting individuals with fraudulent job offers, often impersonating legitimate companies or organizations to lure victims. One reported scam involves text messages claiming to be from Indeed's recruitment team, offering highly flexible remote work with unusually high pay and benefits. The messages request recipients to respond via messaging apps or phone numbers, a tactic commonly used in employment scams to extract personal information or facilitate financial fraud. Indeed has issued warnings that it does not solicit job seekers through such channels and cautions users to be wary of unsolicited offers, especially those requesting communication outside official platforms.
In a related trend, North Korean threat actors are orchestrating sophisticated fake employee schemes to secure remote positions at companies worldwide. These operations involve recruiting individuals to act as fronts for job interviews and team meetings, while the actual work is performed by North Korean operatives. The ultimate goals include stealing intellectual property, siphoning funds or cryptocurrency, and, in some cases, extorting employers. Law enforcement agencies have prosecuted individuals who knowingly participate in these schemes, highlighting the legal risks and broader security implications for organizations hiring remote workers.

Get the infrastructure and lures behind it.
5 events from the most recent confirmed update back to the earliest known activity.
A scam campaign was reported in which fraudsters impersonate Amazon recruiters in unsolicited texts offering unusually high pay for minimal remote work and pushing targets to continue over SMS, WhatsApp, Telegram, or email-to-text. The report highlighted red flags such as Hotmail addresses, vague job details, urgency, and the risk of follow-on fraud including task scams, identity theft, phishing, money mule activity, or malware delivery.
Online Threat Alerts warned of a scam impersonating Warner Bros. Discovery through unsolicited SMS and WhatsApp job offers promising unrealistic remote-work pay for simple tasks like watching videos or reviewing apps. Victims were directed to a fake portal and later pressured to pay fees to unlock higher-tier work or withdraw supposed earnings, in what was described as a phishing and advance-fee scam.
Indeed was noted as warning job seekers that it does not ask for payment or send job offers through WhatsApp, Telegram, or unsolicited phone calls. The warning was presented as guidance to help recipients identify and avoid the impersonation scam.
Reports surfaced of scam text messages impersonating Indeed Recruitment and offering high-paying remote work with unusual tasks such as updating app store data and boosting app views. The messages sought to move targets to further contact channels and appeared designed to exploit Indeed's brand to lure victims into follow-on fraud.
A North Korean operation was reported recruiting people in target countries to act as 'frontmen' for remote jobs, attending interviews and meetings while North Korean operatives performed the work or collected pay. The broader scheme was described as aimed at stealing intellectual property, generating revenue, and in some cases extorting employers, with some unwitting participants later arrested as money mules.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourceonlinethreatalerts.com
Open sourceonlinethreatalerts.com
Open sourceblog.knowbe4.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.