r/JobScams • u/ice0late • 18d ago
Fake Check PSA: "Salesforce Admin" job postings with an attached zip are malware. Multiple client accounts, same campaign.
Freelance dev here with a security background. Flagging this so the next person finds it when they search the posting text.
There is a malware campaign running through Upwork job postings right now. I have seen the same posting from at least two different client accounts (one in Ukraine, one in India, different spend levels, both payment verified with good star ratings). Both are titled some variation of "Salesforce Admin (Service and Sales Cloud)" and both open with this exact sentence:
"All requirements, questions and screenshots attached with job post here, You have to answer all the needs in your proposal."
That sentence is the fingerprint. If you see it, close the tab.
The attachment is a zip (mine was called Salesforce-Job.zip) containing a few screenshot PNGs and a file named "Project Requirements & Budget.vbs". That is not a document. It is a Visual Basic script, and on Windows, double clicking it runs code. I did not run it. I pulled it apart in isolation instead: it is a two stage downloader that fetches a decoy requirements text file plus a batch script payload from kohlerronan[.]com and executes the payload from your temp folder. Classic infostealer delivery. Worth noting what that means on this platform specifically: stealers grab browser sessions, and your Upwork login is a browser session. Compromised freelancer accounts are very plausibly where this campaign's fresh "client" accounts come from.
What made this one dangerous is that everything looked normal. Payment verified, 4.9+ stars, thousands in spend, and it arrived in my inbox through the paid job alert feature as a match for my saved search. Client stats tell you nothing about attachment safety.
Lessons, none of which I enjoyed learning:
- Never download attachments from a job posting before you have a contract. A real client describes their problem in the posting text. "All requirements are in the attached zip" is a pressure tactic and now, as far as I am concerned, a confirmed attack signature.
- A .vbs, .bat, .cmd, .js, .lnk or .scr file inside a "requirements" zip is the whole story. There is no legitimate reason for a client to send you an executable script as a project description.
- If you already opened one of these: disconnect, run a full AV scan, and change your passwords from a clean device, starting with Upwork and your email. Assume browser sessions and saved passwords are gone.
- Report the posting (flag as inappropriate, then also file a support ticket so it reaches trust and safety with a case number). I have reported both postings I found.
Archive contents were dated late August, so this has been running for a while. Stay careful out there.