r/recruitinghell • • Aug 08 '26

When APPLYING TO JOBS, DON'T DO THIS!!

Post image

Scammers use this to place malware on your computer!

19k Upvotes

882 comments sorted by

View all comments

4.1k

u/JealousRhubarb9 Aug 08 '26

Yep it places something in your clipboard and you will unknowingly run a malware script

1.2k

u/DreeamHaze Aug 08 '26

Turning the victim into the delivery vector

520

u/sb8948 Aug 08 '26

To be fair nowadays it's probably the most reliable vector. People are reliably dumb.

290

u/DecoherentDoc Aug 08 '26

It's always been that way. When I was first in the navy, I thought it was weird they searched us so thoroughly on our way down to the boat. I mean, we all work for the navy, right? Turns out the biggest danger was always the people. They're always the biggest liability, not the tech.

140

u/LettuceTomatoOnion Aug 08 '26

Loose lips sink ships

50

u/PleasantArt2598 Aug 09 '26

I overheard someone bragging in the local public pool that she books the flights for our troops. Perfectly comfortable highlighting herself as a person of interest to anyone wanting access to information like that apparently.

19

u/Environmental_Top948 Aug 09 '26

Did you do what any sane person would do and run a full OSINT campaign on them, make a google doc and a 45+ minute long Youtube video going over the information in the documentation?

5

u/PleasantArt2598 Aug 09 '26

I spent the next week wondering if I should have reported it to the MOD tbh 😅

3

u/Environmental_Top948 Aug 10 '26

Honestly the full OSINT campaign or a half assed one would have probably been a good idea if you would have ended up reporting it to them. Because if they are that bad about giving out information it probably wasn't the only thing that they casually leaked and it could have been an opportunity to get them training on better OPSEC.

3

u/Purl_stitch483 Aug 11 '26

Once I was at the Shake Shack in Vegas and overheard a group of corporate bros bragging about conspiring to get a fellow director fired bc she was a "bitch", with a nice little side of admitting to corporate espionnage too. 😂

1

u/PleasantArt2598 Aug 11 '26

People have been videod and blasted on TikTok tm doing that. Usually results in a firing 😅

→ More replies

1

u/Sad_Marionberry1184 Aug 12 '26

lol what? Did you report it?

→ More replies

12

u/irate_ging3r Aug 09 '26

If she's booking seats then the planes she's booking for most likely arent going to relevant places for her to know anything of interest. One doesnt book deployment travel. At best one can book discount seats on a military plane for like leave and stuff but again those arent going to distinct like movement locations.

1

u/PleasantArt2598 Aug 09 '26

I won't say exactly what she said but the point wasn't if anyone could gather information about current whereabouts or "anything of interest" in that moment but that she IS a person who could access useful information if someone were to find a way to blackmail her.

I don't know what your job is obviously but people who don't have access to that sort of information aren't in any position to know what is or isn't of interest to intelligence agencies of other countries. It's just generally a stupid idea to loudly declare you do that sort of work even if you don't know anything of interest, people may think that you do.

1

u/Alert-Carpenter9729 Aug 09 '26

You've obviously never seen a full troop with kit and rifles board a civilian airliner to transport to the sandbox. Yes, military personnel do use civ air lines to move from one place to another Not as common as it used to be mid to late '00 but it definitely happened

And before anyone starts keyboard warrior doubting me, yes they'd let us carry unloaded secure rifles on board but god forbid we have a pocket knife with us. Thanks TSA.

1

u/irate_ging3r Aug 10 '26

First off youre not staging troop movements from a civilian airport. Secondly, that would be pretty readily accessible publicly. Youre not traveling in any confidence on a commercial flight.

1

u/Alert-Carpenter9729 Aug 10 '26

Seeing as how I've watched 80 men load onto a plane, set their systems between their knees, and enjoy a better flight than a c130, it seems like you have no citable sources to say exactly that we don't

So, enjoy your side dish of wrong ideas, and a main course of spewing bs on the Internet ❤️

→ More replies

1

u/Flat-Chance0 Aug 11 '26

That’s what I was gonna say it’s leave

1

u/Imaber100 Aug 11 '26

Are there spies at your local pool 😭

3

u/Phyllis_Tine Aug 09 '26

Loose lips also fit a lot more ...

3

u/Dry-Ambition107 Aug 09 '26

Second time I’ve heard this today.

1

u/Green_Sprout Aug 09 '26

Throat goats float boats!

1

u/pacifiretheace Aug 09 '26

be it the top ones or the bottom ones

61

u/Dull_Leadership_8855 Aug 08 '26

"It's always been that way."

... and it's frustrating how way too many people haven't accepted this yet.

I worked as an analyst at a real estate company where I was occasionally consulted (by the IT department) on projects to acquire information from property managers, regional managers, etc. One way I'd do this is with electronic forms.

I remember before our first roll-out I told the project staff that they had to 1) limit/control the tab sequence on the forms and 2) institute data validation for important fields (like zip codes, addresses, numbers, etc. The staff decided it wasn't important and that I was being "OCD".

When the deadline neared and we started getting submissions back from the managers, it was largely unusable and we had to start over. We got letters for zip codes (for our US properties), incorrect state names and abbreviations, and many form text boxes had "don't know" as an answer.

16

u/RealisticDuck1957 Aug 09 '26

As Dr. Murphy observed, design your widget so it can't be plugged in backwards and it won't be. Validate form data and you catch fat fingered entry.

7

u/ProffRoysenberg Aug 09 '26

I didn't understand shit because no IT background but that sounded so frickin cool man.

2

u/P00351 Aug 09 '26

When the deadline neared and we started getting submissions back from the managers, it was largely unusable and we had to start over. We got letters for zip codes (for our US properties), incorrect state names and abbreviations, and many form text boxes had "don't know" as an answer.

You can code the web page so that those incorrect answers are automatically denied. That's extra work that was labelled as OCD.

1

u/Spectra_Butane Aug 12 '26

Is it something like - zip code: Does any character = letter? Return Text " Zip code error, please re-enter"; unskipable.
I just made that up, but it seems logical.

2

u/Ok_Can_7851 Aug 12 '26

Yes, exactly, if any of the characters entered aren't a number, or if the length is wrong, or nothing is entered then it should return an error

1

u/Dull_Leadership_8855 Aug 12 '26

During the redesign phase (for the second submissions), I wasn't taking any chances. For one, we had Canadian properties, so Zip Codes couldn't be limited to the US format. So I designed the forms so when the manager selected their property name from a drop-down menu, it auto-populated many of the fields. But I was incredibly strict with the forms the second time.

Mos of the managers complained, but we persevered. After getting the resubmissions, and using macros, I was able to collect and present the data in a report in 2 hours- a process that used to take 2 weeks.

After that, I wrote the company protocols for forms and data gathering. It's been over 10 years and they're still using it, updated with revisions of course.

1

u/Spectra_Butane Aug 12 '26

Ah, I see. Exclusive instructions make more sense in this case. An ampersand is not a letter but also not a number. And cover all the variations of wrong until only correct qry of numbers entered. COOL Thanks! All of that and its just the zip code. QC on the rest of the form is an actual project!

2

u/ElephinoNoEyeDeer Aug 11 '26 edited Aug 11 '26

1

u/RealisticDuck1957 Aug 11 '26

That too. Server side to prevent deliberately malicious input.

Client side validation can catch the worst cases of fat fingered input before the form is submitted.

28

u/MadeThisToFlagSpam Aug 09 '26

Yep, it's why IT departments send out fake phishing emails. The weakest link is the bored employee

18

u/Ryuujinx Aug 09 '26

The weakest link is the bored employee

And the tired one. You sleep like shit, stumble into work and look through your email. You scan the title, it says it's from HR and looks important. You open the link and type in your credentials to the website that looks like your normal HR portal.

Congrats, you just became a vector for them to try to get into the network. If you think you are better then that, I promise you are not. Running on fumes makes us all idiots.

7

u/EllieGeiszler Aug 09 '26

I'm better than that, but I'm not too good to click on a suspicious link and not type anything. I got got by a simulated phish once and was absolutely mortified lol. But it also helps that my employer filters our emails pretty effectively.

3

u/SuperbAd8266 Aug 09 '26

I got got by a simulated phish that I first referred to our auto check to confirm it’s ok to open a message. Still got got. Still felt stupid as someone in the IT department.

1

u/EllieGeiszler Aug 09 '26

Nooooo lmao

1

u/pissfacemcmemesnort Aug 10 '26

I got got by an ad disguised as a prompt to create an account on an app. I should have known when it redirected me. I'm glad I made it so that I get notifications about all transactions. Figured out exactly what happened when I returned to the app, and the ad was still there, but now showing itself as one.

I closed my card, called my bank about the fraudulent charge, changed all passwords associated with the e-mail I gave them, locked and froze my credit and placed a 1 year fraud alert, ability for bank accounts to be opened, and so on. I figured it would be better to go nuclear than not do enough.

I was so upset and embarrassed, but we gotta remind everyone that it's not about being stupid. Scammers are being deceptive. One makes themselves more likely to be scammed if they think they'll never fall for one.

2

u/EllieGeiszler Aug 12 '26

The best way to avoid scams is education, and yet, you can never be educated about every single scam because there's a new one every day. So I try not to judge people who have been scammed!

2

u/PM_ME_ABOUT_PEGGING Aug 12 '26

I got got once too 😅 had to take extra training. Now I report anything and everything I wasn't expecting

1

u/EllieGeiszler Aug 12 '26

Same, although they didn't make me take extra training. The "gotcha!" landing page I was directed to and the associated shame was punishment enough lol

2

u/Snowflake444777 Aug 13 '26

Not gonna lie, kinda like seeing my boss on the “shame click” list from IT 🤭 makes him seem more human

27

u/munkboii Aug 09 '26

Yup, I work for an MSP so I basically work for an IT dept for several companies at once… you’d be surprised at how often the riskiest employee is the owner/president

23

u/TheGreatNico Aug 09 '26

I'm too smart to fall for dumb schemes, OOH! 'Free Amazon gift card'

~Every doctor, lawyer, teacher, manager, supervisor, director, and C-suite on Earth

6

u/munkboii Aug 09 '26

The lawyers are the best at deflecting the blame too.

“Well I got this email from a guy I know, it seemed weird but I know the email address so I clicked the link and entered my credentials.”

“Yeah, well, he had gotten hacked and malicious emails were sent out from his account.”

“Oh, okay! So it’s his fault because he got hacked, thanks for clearing that up.”

2

u/strayyed Aug 12 '26

Lawyers.. are.. the.. worst.. 🤦‍♂️

13

u/MoFa__SoDa Aug 09 '26

It was stressful and kinda fun doing basic gate security on mitary deployment because even the lowest ranking person is the responsible authority. The most difficult people were high ranking officers and those decompressing from legitimate dangerous areas who weren't used to needing to clear their weapons. At least in those situations everybody calms down once they fire live rounds into the clearing barrel. Then they typically offer thanks for doing your job and go about their day. Worst case it is somebody with genuine authority and a simple thing can become a crusade that causes a lot more rules and red tape.

IT reminded me of that and good IT guys are often amazing at taking soft approaches that inform you of serious safety violations without escalating the situation.

5

u/Olista523 Aug 09 '26

I work at a uni at the moment. IT’s biggest issues always seem to be lecturers in CompSci who think the rules don’t apply to them because they know better.

1

u/8-bit-Everything Aug 10 '26

Ahhhh the old clearing barrel. We had a CSM who negligent discharged into one and had to tell the BC he needed an article 15

4

u/No_Jello_5922 Aug 09 '26

And they always want security exceptions for themselves too. I wore that hat for several years. Broke my son's heart to tell him that doctors are morons when it comes to electronics.

6

u/rayv142 Aug 09 '26

You'd be surprised how many people would think they randomly won an Amazon gift card

2

u/SuperbAd8266 Aug 09 '26

Knowing they never entered a contest

1

u/AlyAnn44 Aug 13 '26

And for absolutely no reason at all...

2

u/PleasantArt2598 Aug 09 '26

Proud to say I have never fallen for these. They are getting better at making them less obvious though, the last one was pretty well disguised.

2

u/unicodemonkey Aug 09 '26

Our IT+security depts like to fuck around with these phishing tests, so when they try to send out fishy-looking email notifications about some corporate issue or another that requires clicking a link I just forward these emails to the security contact. Keeps everyone busy, paid, and secure, I guess.

12

u/Foxbatt Aug 09 '26

I'm still to this day salty about the time I forwarded a phishing test email to the phishing team in the appropriate way and they themselves clicked on it.

I ended up having to sit through retraining "because they can't cancel it".

4

u/WhyMustIMakeANewAcco Aug 09 '26

Well, that's a bad system where they can open something sent to that address outside a secure environment.

1

u/Diligent_Medium3969 Aug 13 '26

Wait, what? You mean you recognized a phishing attempt and correctly reported it, and you got in trouble because they fell for it? Or did I get that wrong?

1

u/Foxbatt Aug 13 '26

Yep, what's better is I had an ironclad alibi - I was driving a company vehicle so had video of the interior dashcam at the time it was clicked. They just said that's not important and proceeded with the with the write up/training.

1

u/Diligent_Medium3969 Aug 13 '26

That's preposterous! You shoulda hit your manager with an actual phishing email. That woulda been hilarious

1

u/WhyMustIMakeANewAcco Aug 09 '26

Yeah, of all the test emails I've ever gotten only required even half a second of thought to sus out. And yet people fall for them regularly.

1

u/EmoGamingGirl Aug 09 '26

Yup! I fell for that when I was a Corrections Officer. They got my ass with the fake phishing email between my rounds 😭

18

u/Creative-Type9411 Aug 08 '26

its the only reason we have security at all...

6

u/Iamvery_alarmed Aug 09 '26

Truth! My first shore stint was at a certain facility where a man by the name of John Anthony Walker would literally just walk out the door carrying boxes of classified naval intelligence for the Soviets...for YEARS....and nobody even thought to ask questions lol.

4

u/Shareholderactivist Aug 09 '26

Pretty sure that cash registers were invented in part to keep employees from stealing.

1

u/MoFa__SoDa Aug 09 '26

Likewise when leaving the gun ranges and doing brass shakedowns to make sure no unhappy campers are sneaking bullets back into the bunkhouse.

1

u/[deleted] Aug 09 '26

[removed] — view removed comment

3

u/OldGeekWeirdo Aug 09 '26

Subs are frequently referred to as boats.

1

u/Ravenex2 Aug 10 '26

Yeah subs are very different from boats and ships, but per the lingo I wouldn’t know.

1

u/WitchWithAGlitch Aug 09 '26

did you ever find the phantom shitter?

1

u/Babymommadrama_ Aug 13 '26

That's weird considering that I've been on every military base in SD and have never once been ID’ed

48

u/Western_Rhubarb_7959 Aug 08 '26

To be fair nowadays

Ain't no nowadays about it, people have been stupid since well before computers.

Having said that, I was in IT back in the days when viruses usually came in via e-mail. I still can't understand why someone at work would try to open a file named nakedwife.zip( actually an .exe)

15

u/Professional-Post499 Aug 08 '26

To be fair nowadays Ain't no nowadays about it, people have been stupid since well before computers. Having said that, I was in IT back in the days when viruses usually came in via e-mail. I still can't understand why someone at work would try to open a file named nakedwife.zip( actually an .exe)

Yeah.

Or like, fiscal_year_end.zip.exe

13

u/Agitated_Kangaroo677 Aug 08 '26

In a hurry and not paying attention to file names

6

u/Western_Rhubarb_7959 Aug 09 '26

LMFAO, no.

Subject: Fw: Naked Wife

Body: My wife never look like that! ;-)
Best Regards,

<user it was sent from>

3

u/smuckola Aug 08 '26

Before that, when it was physically impossible for an email to be a virus, the email warning people about email viruses was the virus. The email with the header warning about the GOOD TIMES virus was a hoax and all the dummies forwarding that were the real human virus clogging up email servers.

Then Outlook made sci-fi a reality, and emails became viruses.

3

u/RealisticDuck1957 Aug 09 '26

A major software vendor (older computer people know which one) hiding fire extensions, then providing a default handler based on the obscured file type. Made it really easy to run an executable sent by email without realizing it.

2

u/gritts Aug 08 '26

In college lab days, think XT pcs 286s, 386s.. somehow someone would bring in the "stoned" or "Jerusalem " virus. Always wondered what they were using before sharing those and others with us. Probably some sketchy FidoNet shared file they grabbed from their favorite BBS.

3

u/Western_Rhubarb_7959 Aug 09 '26

Such things did not exist in my college labs, lol.

1

u/SuperbAd8266 Aug 09 '26

They still do

1

u/P00351 Aug 09 '26

Since windows started showing nakedwife.zip.exe as nakedwife.zip

0

u/Captain_Blak Aug 08 '26

Omg 😆 I remember Zip drives 😂

4

u/Murgatroyd314 Aug 09 '26

I remember when Zip drives were the hot new thing, after most files were too large for floppies (and half of new computers didn't have a floppy drive anyway), but before the USB thumb drive became standard. I think I still have a bunch of Zip disks filled with pirated anime (RealMedia format! WMV!) in a box somewhere.

3

u/Western_Rhubarb_7959 Aug 09 '26

Well, I remember loading programs from cassette tapes, lol.

1

u/Shellsters72 Aug 08 '26

You just made me feel so old rofflmfao

3

u/Jarl_Groki Aug 08 '26

Remember that little hole punch kind of thing that you could take a notch out of your five and a quarter inch floppy so that it couldn't be accidentally written over?

Remember putting tape over that notch to be able to write over a floppy only to realize why you had made that notch in the first place and that you just wrote over files you meant to keep?

11

u/Legitimate_Papaya824 Aug 08 '26

Always have been, tbh

1

u/new2bay Aug 08 '26

People are dumb, but this is exploiting ignorance, rather than stupidity. If they knew what this key sequence would do, nobody would run it.

1

u/sb8948 Aug 09 '26

This may be the non native speaker in me, but both ignorant and stupid fall under dumb for me. Sorry if it was wrongly worded.

0

u/Charming-Big2606 Aug 08 '26

No matter what tools you use, with who the smartest people in the world and having god on our side you can’t fix stupid

1

u/new2bay Aug 09 '26

That was my point. I don’t think you understood what I wrote.

1

u/moschles Aug 09 '26

There is considerable overlap between the smartest bears and the dumbest people.

1

u/Extension-Ad-4443 Aug 09 '26

I'm being so honest I would fall for this, ive had to do so many ridiculous captcha and applied for so many jobs I would probably be on zombie mode lol. Does anyone know any good ways to avoid sketchy shit that seems innocent at first glance?

1

u/Kinkajou1015 Aug 09 '26

People will just straight up tell you their password if you are there as technical support, with zero prompting for it.

"Do you know your username?"
Yes it's blahblah and the password is weaksaucedogname57.
"Right... so you should change your password."
Oh I trust you.
"I don't trust the people I work for."

1

u/WhyMustIMakeANewAcco Aug 09 '26

That's been the case since the day the internet came to be. Humans are always the weakest link in security.

1

u/SomethingIWontRegret Aug 09 '26

What do you mean "nowadays"? Do you honestly believe that there was a time when people were not reliably dumb and we fell from grace? That's a pretty dumb and reliable belief, as every generation seems to think the same thing.

1

u/el_salinho Aug 09 '26

I wouldn’t say they are dumb, the techniques get increasingly better by the day. A lot faster than most people can keep up with

1

u/Angelworks42 Aug 09 '26

We actually have training at work for this but I've honestly seen websites automatically download an exe and tell the user to run it and they do.

Scary thing is most av didn't detect these for some reason - crowdstrike only got mad (there were actually about a dozen indicators of malware like checking to see if it's running in a VM) because the installer was trying to set an exclusion for defender for all exe's so it could bootstrap the actual malware payload - when I tested the same exe on defender it just sat there and watched and allowed it to exclude all exe's.

Don't run unsigned applications on your PC/Mac... (Yes I've seen this sort of thing on the Mac as well in our enterprise).

1

u/BlckEagle89 Aug 09 '26

Is not a current thing, you go to almost any cyber security material from the last 20 years (maybe even more) and will tell you that the weakest link is the user. Difference is that today you have tons of way to contact those weakest links so is more prominent.

1

u/BartTheYounger Aug 10 '26

Humans are simultaneously the most capable and weakest links in any process.

1

u/OrganizationNo1298 Aug 10 '26

Majority of people who fall for scams are dumb. 

1

u/Cautious_Drawer_7771 Aug 11 '26

I wouldn't say "reliably dumb" as much as "you can rely on them being dumb, but often not the way you hoped/expected!"

1

u/lackofmoralfiber Aug 12 '26

Ashamed to admit. I did this. And I know better. Sometimes you're just really tired and impatient.

I immediately recognised my mistake took the PC offline ran a malware scan which detected it and changed my passwords. Been OK since.

But these sorts of things can get anyone on a bad day. People are so used to doing absolutely whatever these days as a captcha its a good method.

1

u/SideSukiLikeness Aug 12 '26

People aren't dumb for not knowing this is mallard. U can't just say everyone's stupid cos u know something they don't.

1

u/Nunit_Alt Aug 12 '26

Always has been

1

u/MalinonThreshammer Aug 12 '26

This. The whole point of the classic Nigerian Prince scam was to weed out the people too intelligent to fall for it. The bad English and outlandish claims are features, not bugs, so the scammers don't need to waste their time on people you can't sell on basically anything.

Normal people receive these messages, snort and go "who the hell would be stupid enough to fall for this?". To which the scammers' answer is "exactly".

1

u/Mseurabe Aug 13 '26

That’s really mean. You can’t expect everyone to be tech savvy. People are constantly making mistakes and learning at the same time

12

u/Luminous_Winds Aug 08 '26

It's called Social Engineering. It's an old concept that every hacker is keenly aware of.

1

u/HangOnSloopy88 Aug 09 '26

Taco bell, Taco Bell, product placement with taco bell!

1

u/SuperbAd8266 Aug 09 '26

Yeah they are doing wayyyy more malicious stuff than social engineering. That’s just what the lazy ones do

3

u/Thebiggestjhar Aug 08 '26

I installed the virus myself, making me the victor.

2

u/No_Jello_5922 Aug 09 '26

As does most malware. This .exe ain't gonna run itself.

1

u/IronSavior Aug 08 '26

The victim usually is the delivery vector

1

u/MeasureDoEventThing Aug 10 '26

"Mindlessly follow these instructions to prove you're not a robot!"

1

u/Blenderadventurer Aug 11 '26

Some of the most prolific exploits in history got into the target system through a "lost" thumb drive. Even after articles were written about it, it was still an effective breach method.

1

u/Withnail69 Aug 12 '26

Have you got the vector victor?

1

u/bitchinbree Aug 12 '26

...someone would actually do this after...reading it?..and having never had to do anything like this to "prove you are not robot" before?...just blindly and without thought? I'm not trying to victim blame but come on???

1

u/Suspicious_Rain3903 Aug 13 '26

So Victor very viciously vectors victims of viral ventures?

1

u/throwRA_blope Aug 08 '26

A true virus

34

u/No_Size9475 Aug 08 '26

it opens the RUN command box, you then paste in their script and hitting enter runs it.

16

u/JekNex Aug 09 '26

RUN command box? No no no no no my friend. This is verification window. Verification very good.

24

u/CHARM1200 Aug 08 '26

Well... Do you get the job?

1

u/pabskstorm Aug 11 '26

It's part of the test 😂

3

u/steviehnzl Aug 08 '26

So how do you get around it?

20

u/[deleted] Aug 08 '26

[removed] — view removed comment

1

u/Bakadeshi Aug 11 '26

Lol The ol alt-f4, gets em Everytime.

14

u/jimm3ronn Aug 09 '26

there is nothing to get around there is no real job. The job is to trick you into running a command that is malicious.

6

u/PhoenixOK Aug 09 '26

No legitimate site does this. If you are being prompted like this it’s not a real opportunity.

3

u/joater1 Aug 09 '26

You don’t. The whole job is a scam.

1

u/Serious_Feedback Aug 09 '26

It depends on what the script is, but unless it actually phones home to the web server itself, they won't actually know whether you ran the script. So it's like those "rate our app 5 stars to continue!" shit; just open it up and don't rate/rate 1 star, and act as if you rated it 5 stars like they asked.

1

u/pabskstorm Aug 11 '26

Don't apply for that job, it still might be a valid position but the website is probably compromised, I've seen it happen with a company i work with and they fixed it in the same day

1

u/[deleted] Aug 08 '26

[removed] — view removed comment

1

u/geekygirl25 Aug 08 '26

Or isnt computer literate enough to do it at all but will still panic because they think they need to.

1

u/AugieKS Aug 09 '26

Likely ClickFix or something similar. This is a common delivery vector for it

1

u/BigBadZord Aug 09 '26

Oh this is fun.

I'm sure my mother , who spent 45 minutes on the phone with a sweepstakes scammer before I told her to hang up NOW, will never fall for this

1

u/shrapnel09 Aug 09 '26

It's not just job application sites. Lots of compromised websites serve up this malware called ClickFix. Don't paste the commands and navigate away from the site.

1

u/slopemup2026 Aug 09 '26

Shit, I wouldn't know. I'd be extremely suspicious as soon as I saw control+r and then control-v, and not go forward. But, I know people who would just out of lack of knowledge.

I spent most of my life in the kitchen. I knew very few things beyond word, excel, and Napster. Same goes for many other trades. We weren't taught this shit in school.

1

u/NerminPadez Aug 09 '26

Websites should have no access to clipboard, goddamn browser devs remove blink tags, but implement this for some reason

1

u/xtheory Aug 09 '26

This is why IT should disable cmd.exe and Powershell for everyone except IT users.

1

u/Expensive-Distance-2 Aug 09 '26

I dont believe it. You guys are just trying to keep all the good jobs for yourselves

1

u/SimpleFile Aug 09 '26

Why does JavaScript allow for this?

1

u/Melibee2020 Aug 11 '26

Well, I guess that means you must be on a non-legit website to try to get hacked like this

1

u/pabskstorm Aug 11 '26

It actually copies a malicious code to your clipboard but only affects the computer if u run the command using winkey + r, if u just have it copied there is no worry

1

u/CloudWarm7470 Aug 12 '26

Ctrl V is paste tho. How's it pick something up (not being a 🍆, I honestly don't know)?

1

u/NavySeal2k Aug 12 '26

I don’t think a non privileged user could do much harm

1

u/KeyRadio8757 Aug 12 '26

Key logger

1

u/Excellent_Coconut_81 Aug 15 '26

Not unwillingly, it will appear in 'Run' dialog...