Fortune | FORTUNE 前天 04:55
警惕求职陷阱:网络犯罪分子盯上求职者
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

网络安全公司DNSFilter的最新数据显示,网络犯罪分子正采取新的卑劣手段,将目标锁定在求职者身上。研究发现,包含“jobs”的恶意域名高达8,724个,其中绝大多数为新注册或近期发现。同时,包含“careers”的恶意域名也有1,161个。分析师指出,当前全球经济形势不佳,失业率上升,求职者更容易成为诈骗的受害者。犯罪分子不仅针对求职者,也利用伪造的简历和钓鱼邮件攻击招聘经理。为防范此类风险,求职者应仔细核查域名,警惕过于诱人的职位信息,并及时与招聘方核实。

⚠️ **网络犯罪分子瞄准求职者:** DNSFilter的数据显示,包含“jobs”的恶意域名数量惊人,其中大部分是新注册的,表明这是一个日益增长的威胁。这反映出犯罪分子正在利用当前经济环境下求职者的脆弱性。

📈 **经济形势加剧风险:** 美国失业率的上升和招聘活动的疲软使得人们更迫切地寻找工作,这为网络犯罪分子提供了“攻击的绝佳目标”。求职者在经济压力下更容易放松警惕,从而落入陷阱。

🎣 **招聘经理与求职者均是目标:** 除了直接攻击求职者,犯罪分子还会通过包含恶意软件的简历来攻击招聘经理,并利用深度伪造等技术提升“假IT工作者”骗局的欺骗性。这意味着整个招聘流程都可能存在风险。

🛡️ **防范招聘诈骗的建议:** 求职者应仔细检查域名,避免使用带有过多连字符或奇怪后缀的链接。如果某个职位听起来好得令人难以置信,那么它很可能就是假的。与招聘经理联系以核实招聘通知是保护自己的有效方法。

New data from DNSFilter shows that cybercriminals are stooping to a new low: targeting job seekers.

The cybersecurity company found 8,724 malicious domains containing the word “jobs,” with the overwhelming majority (86%) newly registered or observed. Meanwhile, 1,161 malicious domains contained the word “careers.”

Prime targets. Gregg Jones, an intelligence analyst lead at DNSFilter, told IT Brew that while it isn’t new for cybercriminals to target job seekers, the problem has been amplified by “current world conditions” that make those on the hunt for employment especially vulnerable to scams. While the US unemployment rate stood at 4.3% in August—the most recent published figure from the Bureau of Labor Statistics (BLS) due to the ongoing government shutdown—job hiring has continued to falter. According to the BLS, US employers added 22,000 jobs in August, a sharp decline from 142,000 in the same period last year.

“​​The economy is not so great…people are struggling to find jobs, some people are struggling to keep jobs, and it’s that constant ebb and flow of ‘where’s the good sheep for the wolf to go attack?’” Jones said.

It’s a tough market. Job seekers shouldn’t take the interest from cybercriminals personally, as malicious actors have placed targets on the backs of hiring managers, as well. In May, Arctic Wolf Labs released details about a spearphishing campaign hurled by threat group Venom Spider at hiring managers, with threat actors using résumés laced with malware when applying for jobs. Recruiters also have been grappling with the growing fake IT worker scheme, which has grown in sophistication thanks to deepfake technology.

How to dodge hiring scams. DNSFilter suggests job seekers double-check domain names and stay away from links with “excessive hyphens or strange extensions.” Jones added that if a job offer looks too good to be true, it probably is, and said individuals can always reach out to hiring managers to verify recruitment notifications: “No one should ever chastise you for being extra careful.”

This report was originally published by IT Brew.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

求职诈骗 网络安全 网络犯罪 DNSFilter 招聘陷阱 Job Scams Cybersecurity Cybercrime Hiring Scams
相关文章