CommencementUncategorizedHackers are using false promises of employment at Meta, Disney, Coca-Cola and...

Hackers are using false promises of jobs at Meta, Disney, Coca-Cola and Spotify to steal users

NordVPN's Threat Intelligence research unit announces that it has found a sophisticated phishing campaign targeting job seekers posing as some of the world's most recognized companies. The operation exploits the names of global giants such as Meta (and its subsidiaries, such as Facebook and WhatsApp), Disney, Coca-Cola and Spotify to steal victims' Facebook credentials and hijack their accounts.

The investigation revealed a multi-stage operation. In it, attackers use hidden domains (“HUB”), referral link activation mechanisms and realistic job advertisement interfaces to guide victims along a carefully constructed path. The final step redirects them to a fake Facebook login page designed to capture their credentials.

Banner promocional da Forhold para gestão de varejo com convite para teste gratuito de 30 dias

“Job candidates are particularly vulnerable because they are already used to sharing personal information and following instructions from unknown contacts,” says Domininkas Virbickas, chief product officer at NordVPN. “These campaigns take advantage of this trust by using polished communications and convincing fake career portals that are virtually indistinguishable from the real ones.”

The campaign starts with a cold email, usually sent through legitimate services like Google AppSheet to bypass spam filters. These messages look polished and professional, with impeccable grammar and a tone that mimics real recruiting approaches. Contact lists are likely compiled through automated data collection from platforms like LinkedIn or obtained from previous data breaches.

E44114dc 2c86 429c 844f 61828abc0471

The link in the email directs victims to a “HUB” domain (such as careers.meta-findyourjob[.]com). These sites are designed with a built-in circumvention mechanism. If someone, whether a security analyst or an automated scanner, visits the domain directly, they will only see a generic, inert page with no interactive functionality.

This way, malicious content is only activated when the website is accessed through a specific referral link embedded in the phishing email. This referral link acts like a key, unlocking a clickable “Search a Job” button that would otherwise remain hidden.

8a0ddfed 7191 4728 b5d7 014fe82e4dd3

As soon as the victim clicks on the link, they are redirected to an intermediary domain that simulates a legitimate job portal. The interface allows users to browse seemingly trustworthy vacancies from the counterfeit brand, reinforcing the illusion that they are participating in a real selection process.

Examples include plus.jobfusion-mt[.]com and official.professionlaunch-mt[.]com for Meta, careers.coca-contactnow[.]info for Coca-Cola, connect.spotifycareerapply[.]com for Spotify, and jobquest.wdcfuturesteps[.]com for Disney.

896b23e2 3f61 4325 bb9a 7a5b5403fa4e

The trap closes when the victim clicks on “Apply” or “Send application”. Instead of a job application form, she is redirected to a phishing page that requires her to log in via Facebook to “proceed with the application.” This page is designed to capture the victim's Facebook credentials, giving attackers full control of the account and potentially all services linked to it.

7ccab600 5210 4d75 a8b6 6d204ec86d44

The campaign highlights a growing trend of attackers using trusted brands and professional contexts as weapons to circumvent victims' natural skepticism. Because the phishing flow mimics a real recruitment process so accurately, even cautious users can be caught off guard.

NordVPN recommends 3 actions that users should take when receiving any type of email with job openings:

  • Check the URL before entering any credentials. Legitimate companies host careers pages on their official domains, not on third-party sites with unusual names. The same applies to social media login requests. “Sign in with Facebook” buttons on legitimate platforms will always redirect you to the official facebook.com domain. If the login page is hosted at an unknown URL, it is likely a phishing attempt.
  • Enable multi-factor authentication (MFA) on all social media accounts. Even if credentials are compromised, 2FA can prevent attackers from gaining access.
  • Never trust unsolicited job offers that arrive via email or messaging apps, especially those that pressure you to act quickly.

Methodology:

The investigative process used public research methodologies (OSINT – open source intelligence) and the consequent need to corroborate and validate the data obtained through cross-referencing.

In particular, the core of our data collection strategy included the use of specific “dorks” (advanced search strings) applied to the main generic search engines, as well as the use of specialized search engines to index domains, websites and devices exposed on the internet. Among these specialized tools, we made extensive use of search engines for the Internet of Things (IoT) and service platforms similar to Shodan, such as Fofa.io and Shodan.io. These tools allowed us to identify not only domains, but also exposed services and ports, revealing potential vulnerabilities or unintended exposures.

The main objective of this layered research methodology was twofold:

  • To obtain the most exhaustive and complete view possible of the landscape of digital entities involved.
  • To accurately identify domains that have actually been compromised, going beyond merely identifying theoretically vulnerable domains.

This detailed analysis ensured that conclusions were based on verified data and that the perimeter of compromised systems was delimited as accurately as possible.

E-Commerce Uptate
E-Commerce Uptatehttps://www.ecommerceupdate.com.br/
A E-Commerce Update é uma empresa de referência no mercado brasileiro, especializada em produzir e disseminar conteúdo de alta qualidade sobre o setor de e-commerce.
RELATED MATTERS

LEAVE AN ANSWER

Please enter your comment!
Please enter your name here

RECENT

MOST POPULAR

RECENT

MOST POPULAR

RECENT

MOST POPULAR