Job Seekers Under Attack: Three Emerging Threat Actors Identified

Job Seekers Under Attack: Three Emerging Threat Actors Identified

A new wave of highly sophisticated recruitment frauds has emerged, capitalizing on both economic hardships and the hyper-competitive job market to deceive vulnerable job seekers.

These scams blend legitimate recruitment processes with deceptive tactics, making them increasingly difficult to spot. By expertly mimicking real-world job opportunities, these fraudsters successfully manipulate victims into surrendering money and personal data.

Researchers have tracked three distinct threat groups targeting job seekers globally. The first uses advanced fee fraud while posing as tech companies, the second operates a region-specific scam impersonating a logistics recruitment firm in 18 countries, and the third impersonates the Singapore government to steal national IDs and compromise Telegram accounts.

These diverse attack methods underscore the rapidly changing landscape of job-related cyber threats.

In 2023, U.S. job-related fraud losses surpassed $500 million, more than double the previous year’s figure of $200 million, according to the Federal Trade Commission. This surge highlights both the growing sophistication of these scams and the increasing number of vulnerable individuals, driven by economic instability, rising living costs, and the growing prevalence of gig economy jobs.

Netcraft researchers have found that these criminal operations are carefully designed for persistence and scalability, making it difficult for detection systems to catch them.

Their findings show that these scammers use multiple identities throughout the scam process—one for initial contact and another for executing the fraud—allowing them to manage large volumes of victims while minimizing the chances of detection, even when communication channels are interrupted.

These criminals have honed their schemes to exploit specific weaknesses in how job seekers assess job offers, particularly those drawn to flexible working conditions and high salary promises—traits that have become even more appealing in the post-pandemic job market.

The Celadon and Softserv Fraud Scheme

Among the most active scams uncovered, the Celadon and Softserv operation starts with unsolicited messages on platforms like WhatsApp and Telegram, where attackers pose as recruitment consultants claiming to have received job applications from potential victims.

These initial communications often come from international numbers, creating a façade of authenticity while complicating the verification process for targets.

Once contact is established, victims are directed to engage with a second persona who shares job details, typically featuring outrageously high pay for simple tasks. Netcraft’s analysis revealed that these scammers offer payment through cryptocurrency (USDT) and require victims to sign up on specialized fraudulent domains such as celadonsoftapp[.]vip, which are designed to appear legitimate but are entirely fake.

The scam proceeds in stages, gradually increasing the victim’s investment. After signing up, victims are given a small “credit” to their account, followed by requests for them to deposit actual funds to “unlock” higher-paying tasks, thereby perpetuating the cycle of fraud.

Task Selection Interface (Source: Netcraft)

The task selection pages are crafted to resemble widely recognized app icons, creating an illusion of trustworthiness.

An in-depth analysis of the infrastructure uncovered that this cybercriminal group managed nine distinct platforms between May and November 2024, each with nearly identical visual designs and shared server setups.

These domains are shielded by Cloudflare and hosted via Gname, indicating the group’s vast reach and methodical effort to ensure the persistence of their operations.

To evade detection, the attackers employ a variety of countermeasures, including requiring unique registration codes for site access, adding login barriers that hinder security investigations, and periodically updating the site’s design to avoid detection and keep the fraud running smoothly.

Earlier Version of the Celadonsoftapp[.]vip Login Page from May 2024 (Source: Netcraft)

The platform’s design evolution, particularly a shift towards more polished, professional-looking interfaces by late June 2024, highlights the attackers’ continuous improvement in their deceptive methods.

Job seekers are advised to stay alert for red flags such as communication strictly through messaging platforms, suspiciously high salary promises, demands for cryptocurrency payments, and any requests for upfront deposits before job engagement.

More Articles & Posts