DEV Community

Cover image for Interview Campaign: Attacking your hopes
Soradll
Soradll

Posted on

Interview Campaign: Attacking your hopes

Here we are looking for jobs, getting in touch with a lot of recruiters, joining interviews, and someone out there sees an opportunity. Have you ever gotten one of those phishing emails that usually goes like:

The job search have gotten so dire that now any threat actor can use this as an opportunity to exploit your hopes. Honestly, with a little bit of recon and enough motivation anyone can do this. You research companies, you buy a domain that's 5–10 days old because the domains are so fresh, safety scanners haven't flagged them as malicious, yet.

You buy a bunch of them. Then use Cloudflare to mask your origin servers. Or better yet if you want to use a whole infrastructure for it and go even above and beyond, you use a modular front-end so you can swap it to a different brand any time of day for whoever you are targeting. 

I think it is not about how structured it looks or how much time they spend on it looking like a legitimate business, it feeds off of our uncertainty and urgency to get it together and find a job, grow, have a real career amidst of all of this Artificial Intelligence news and Global crises. 

A psychological manipulation to be precise. 

And if you are looking for a job in tech, the shtick usually goes like this. You applied through one of these sites developed by none other than these actors, what happened first? Yes, you guessed it. You have just given your information. On attacker's side that's one quota achieved. 

After you applied, there's an email maybe a couple hours later, asking you for an interview. You are so happy now. See they are not using the desperation or fear like most social engineering attacks. It is your hope. And that hope is the thing that keeps you clicking things, writing your information on those little boxes.

In the email there is a file that probably named as "InterviewProcess.pdf" or "JobDefinition.pdf or something like that. You clicked on it. And it was probably a malware but you are still unaware, still hoping. So you downloaded and read this successfully structured pdf until the last moment.

Then they interviewed you. It felt like a real interview. You have given your all and you have been preparing for months. It went so well, right? The best interview you have ever had. It felt like someone finally saw your potential. You have no doubts now. It is happening for you. Some of these campaigns stops here and they go AWOL. But the one you applied seems to be looking even more legit. They want you to meet the team leader. Can you believe it?
 
Team leader goes above and beyond, explain the job with more and more details. But now the catch is coming. They want you to deposit some money, you need to buy your own computer and other resources before starting. Now you are suspicious. You didn't want them to think it so you smile and nod until the interview ends. You'll never call them again. 

Is it over? Do you think nothing happened? Sorry, love.

If it is a big campaign, you'll get a call couple of months later telling you that your company ,that you didn't know you owned, is in great debt. And that's hoping I guess. Then there is the malware that's already in your computer now and maybe you'll never know about it. 

I believe this was the best case scenario. They are getting more sophisticated by the minute. Their agenda keeps changing, so does their tactics. In amidst of all this hyper-vigilance how are we supposed to do the things that we love to do? I wonder how that feels. 

Let's look at another example to grasp the gravity of the situation. The same process; application, e-mail, interview. They didn't ask for money this time that's good, right? The interview ended, you are hoping, waiting for a callback. Here it is! Another email. It says:

"Phase two of the interview process is a one-week practical evaluation."

Here's your chance to prove yourself. This is your moment to shine and show your skills that you practiced for hours on end. They asked you to do a case study and maybe write some code. You did it. Maybe it has taken you couple of days or a week but you did it after several cups of coffee, tons of delivered food. And you hit send. This time it has taken them a week to reply:

"Great work overall, but we've decided to go with someone else."

What happened there? You worked so hard. You didn't sleep, you ate a lot of unhealthy food to not waste any time cooking, even your blood runs on caffeine now. You know you did a good job. And you still think it was a legit interview. You might have taken the rejection a little bit hard but you think maybe the next time it'll be different. You gained some interview experience. You are still hopeful but what happened was far worse. They stole your work(always sign an NDA just saying). To them it's free labour, to you it was your Hail Mary. 

Since the AI story is on the rise, this kind of exploitations will probably get more common. They need your case studies, your ideas, your stories, your 10 page thesis, your graphic designs to train them. And you have your hope, and your keyboard. And I am not being anti-AI, I am just not into exploiting people for the good of anything else at least without their consent.

It will never end. And it will never end well. Whether it's about money or training models, it will go on and on.

Next I will talk about how attackers use malicious packages hidden inside GitHub repositories to lure in unsuspecting job seekers like us.

What do you think about this kind of social engineering attacks? Have you ever encountered one?

Top comments (1)

Collapse
 
dubugiii profile image
Duygu

Well written , it does the reality check we all need sometimes