“这个求职面试骗局是窃取你谷歌账户凭证的伎俩”

内容总结:
求职季骗局升级:假面试邀请钓鱼窃取谷歌账号,多家知名企业“躺枪”
当前就业市场竞争激烈,求职者处境艰难,诈骗分子趁机作乱,瞄准那些渴望进入知名企业的人群。最新一轮网络钓鱼活动通过伪造面试邀请,冒用阿迪达斯、奈飞、奥多比及国际足联等品牌名义,意图窃取用户的谷歌账户凭证。
就业骗局并非新鲜事,形式五花八门:从短信发送虚假录用通知,到通过谷歌表单散布假申请链接。去年,冒充奈飞的诈骗团伙就曾发起过类似的招聘邮件攻势。不法分子的核心目的,要么是钓取个人信息,要么是以各种虚假入职费用为由,诱骗求职者转账汇款。
骗局手法揭秘
据安全网站BleepingComputer报道,此类骗局主要针对营销行业专业人士,目标岗位覆盖科技、酒店、旅游、餐饮、娱乐及奢侈品等多个领域的高价值企业。
诈骗流程以一封“招聘官”发来的钓鱼邮件开始。这些邮件冒充超过34家公司,邀请候选人预约面谈。骗子利用这些公司真实招聘人员的姓名和照片,降低求职者核实身份时的戒备心。
一旦求职者点击邮件中链接进入所谓“招聘官”的日历,页面会经历多次跳转,最终导向一个伪装成真实面试预约页面的恶意网站。随后,网站会要求求职者使用谷歌账号登录,弹出一个看似谷歌官方认证窗口的虚假登录界面——实际上这只是钓鱼网页的一部分(属于典型的“浏览器内浏览器”攻击手法)。
调查显示,威胁行为者使用了合法人力资源平台“PeopleForce”以及Salesforce运营的一个域名来启动诈骗,但尚不清楚他们是自行注册了账户,还是盗用了他人凭证。
如何识别假面试陷阱
所有骗局都利用人性弱点,例如在竞争激烈的就业市场中收到心仪岗位面试邀约时的兴奋感。若你主动收到招聘方发来的消息(无论是邮件、领英还是其他社交平台),务必保持警惕——尤其当你并未主动投递简历,或机会听起来好得令人难以置信时。如不确定,请直接前往该公司官网的招聘页面核实职位信息。
链接看似指向合法网站并不代表安全。骗子有无数手段伪造网址或重定向流量,让你浑然不觉自己正被钓鱼。请仔细查看最终页面的地址栏,留意是否存在可疑字符或网址花样。
如果对方在预约面试或填写申请表时,要求你输入苹果、谷歌或脸书等第三方账号密码,这绝对是一个危险信号。可以尝试拖拽该弹窗离开主浏览器窗口,或高亮地址栏内容;若无法操作,基本可判定为伪造。另外,使用密码管理器也能有效防范此类“浏览器内浏览器”攻击,因为这类工具只会在真实域名下填充凭证,从而阻断钓鱼行为。
中文翻译:
求职者处境艰难,骗子正利用人们对知名公司的求职渴望实施诈骗。一种新型钓鱼活动通过伪造面试邀请(冒充阿迪达斯、奈飞、Adobe 和国际足联等品牌)窃取用户的谷歌账户凭证。
招聘骗局屡见不鲜,形式多样——从短信发送虚假工作机会到通过谷歌表单分发虚假申请。去年,冒充奈飞的骗子甚至开展过类似的招聘邮件活动。不法分子通常试图窃取个人信息,或诱骗求职者支付各类(虚假)入职费用。
虚假面试骗局如何运作
据 BleepingComputer 报道,这类招聘骗局主要针对市场营销专业人士,他们寻求科技、酒店、旅游、餐饮、娱乐和奢侈品等多个行业的高价值公司职位。
诈骗始于来自超过34家公司之一的"招聘人员"发送的钓鱼邮件,邀请候选人安排会议进一步讨论。骗子使用这些公司真实招聘人员的姓名和照片,使求职者在核实真实性时不易起疑。
若求职者点击链接进入招聘人员的日历,会被多次重定向,最终落入看似真实面试预约页面的恶意网站。随后会被提示用谷歌账户登录,弹出看似谷歌认证窗口的虚假登录界面,实则只是钓鱼页面的一部分(属于浏览器中的浏览器攻击)。
威胁行为者似乎使用名为 PeopleForce 的合法人力资源平台和 Salesforce 运营的域名来发起诈骗,但尚不清楚他们是创建了账户还是使用了被盗凭证。
虚假招聘骗局的征兆
与所有骗局一样,骗子利用情感弱点——比如在竞争激烈的就业市场中被心仪职位招募的兴奋感。若通过邮件、领英或其他社交平台收到招聘人员的主动联系,请谨慎对待——尤其当你未申请该职位或机会好得令人难以置信时。如不确定,请直接访问公司招聘页面查找职位信息。
日历或申请链接看似指向合法网站并不意味着安全。显然,骗子有多种方式伪造网址或重定向流量,使你难以察觉被钓鱼。请仔细检查最终窗口的地址栏,留意隐蔽字符或其他网址欺诈手段。
若被要求输入单点登录凭证(如苹果、谷歌或脸书)来预约面试或填写申请,这属于危险信号。尝试操作弹出的窗口(如拖离主浏览器窗口或高亮显示网址)。若无法操作,极可能是伪造的。密码管理器也能防御浏览器中的浏览器攻击,因为这些工具仅在合法域名下填充凭证。
英文来源:
It's rough out there for job seekers, and scammers are preying on candidates hoping to get hired by well-known companies. A new phishing campaign uses fake interview invites—impersonating brands like Adidas, Netflix, Adobe, and FIFA—to steal users' Google account credentials.
Employment scams are nothing new, and they come in a variety of flavors, from fake job offers sent via text to fake applications distributed via Google Forms. Netflix impersonators even ran a similar recruitment email campaign last year. Bad actors are typically trying to phish personal information or convince you to send them money for various (fake) onboarding expenses.
How the fake job interview scam works
As BleepingComputer reports, this job scam primarily targets marketing professionals looking for positions with high-value companies across multiple sectors, including tech, hospitality, travel, food, entertainment, and luxury goods.
The fraud begins with a phishing email from a "recruiter" at one of more than 34 companies, inviting candidates to schedule a meeting to discuss further. Scammers appear to be using the names and photos of real recruiters at these companies, making them less likely to raise suspicion if targets try to verify their legitimacy.
If a job seeker clicks the link to the recruiter's calendar, they'll be redirected multiple times and ultimately land on a malicious website designed to look like a real interview scheduling page. From there, they'll be prompted to sign in with Google, which launches a fake login interface that looks like Google's authentication pop-up but is actually just part of the phishing page. (This is an example of a browser-in-the-browser (BitB) attack.)
Threat actors appear to be using a legitimate HR platform called PeopleForce and a domain operated by Salesforce to initiate the scam, though it's not clear whether they created accounts or are using stolen credentials.
Signs of a fake job scam
Like all scams, this one preys on emotion, like the excitement of being recruited for a highly desirable position in a competitive job market. If you receive an unsolicited message from a recruiter, whether via email, LinkedIn, or some other social platform, proceed with caution—especially if you haven't applied for a job or the opportunity sounds too good to be true. If you're not sure, go directly to the company's careers page to find the listing.
Just because a calendar or application link appears to go to a legitimate site doesn't mean you're safe. Obviously, scammers have many ways of spoofing URLs or redirecting traffic so you don't realize you're being phished. Look carefully at the address bar on the final window for sneaky characters or other URL tricks.
If you're being prompted to enter single sign-on credentials (such as Apple, Google, or Facebook) to schedule an interview or fill out an application, this is a red flag. Try to interact with the pop-up, such as by dragging it away from the main browser window or highlighting the URL. If you can't, it's likely a fake. A password manager can also protect against BitB attacks, as these tools won't fill credentials, except on the legitimate domain.
文章标题:“这个求职面试骗局是窃取你谷歌账户凭证的伎俩”
文章链接:https://news.qimuai.cn/?post=4546
本站文章均为原创,未经授权请勿用于任何商业用途