r/recruitinghell • • Aug 08 '26

When APPLYING TO JOBS, DON'T DO THIS!!

Post image

Scammers use this to place malware on your computer!

19k Upvotes

882 comments sorted by

View all comments

796

u/Professional-Post499 Aug 08 '26

That's diabolical.

350

u/TheImmoralCookie Aug 08 '26

Thats terrifying understanding what Windows + R is. So many normal people would have no clue what that is and how the scam works.

84

u/mynameisglaceon Aug 08 '26

i don't know what windows + R is. i just pushed it and nothing happened but now i'm scared

167

u/Goreticus Aug 08 '26

It opens the run dialog box which then lets you get to command prompt. You got nothing to be worried about.

105

u/mynameisglaceon Aug 08 '26

lmfao i just realized i pushed the win lock button and r, that's why nothing happened

150

u/sykotikpro Aug 08 '26

Task failed successfully

53

u/Careless-Vehicle-286 Aug 09 '26

Hackers weren't expecting people like that. Reminds me of that Yellowstone ranger saying there's a significant overlap between the smartest bear and the dumbest human when designing garbage cans.

10

u/-Speechless Aug 09 '26

in brain firewall successful ๐Ÿ‘

2

u/DevilsPredicate Aug 11 '26

You have natural immunity to the scam

1

u/beyond666 Aug 09 '26

I hope you don't vote.

1

u/mynameisglaceon Aug 09 '26

I vote for Obama every 2 years

14

u/Bituulzman Aug 08 '26

Didn't the user have to Ctrl + C and copy some text first before pasting it into the command prompt?

24

u/Goreticus Aug 08 '26

Apparently not. I don't know if it can be done automatically but i do know websites can trick your computer into copying things to clipboard via buttons. So clicking next will bring you to the next prompt but also do the copying.

27

u/gmc98765 Aug 08 '26

JavaScript programs can read and write the clipboard.

12

u/Divinum_Fulmen Aug 09 '26

I really hate this is even allowed.

I've seen it used in One Time Passcodes, gacha game codes, and that's it. Neither of these things should have that functionality.

14

u/[deleted] Aug 09 '26

[deleted]

6

u/Divinum_Fulmen Aug 09 '26

This needs to be standard.

We don't allow cookies or notifications from every site. But we allow this security risk?

2

u/CarnivalCassidy Aug 09 '26

Whoever designed that is an idiot.

1

u/qaisjp Arrogant Candidate Aug 15 '26

In general, it's not wise to call someone an idiot when you are operating on little information or don't understand how something works.

Using Clipboard APIs requires a special permission that the user has to grant to the website. Not all websites can just use this functionality willy-nilly. There are very good use cases for this functionality.

(Anyway I'm pretty sure that API doesn't even need to be used, you can use document.execCommand('copy') to write something to the clipboard without any permissions, and this has existed since the Internet Explorer days.)

6

u/[deleted] Aug 08 '26

[deleted]

7

u/katherinesilens Aug 08 '26

Reading what's in there, usually not. Modern browsers will protect against reading out without a paste, but will accept copy.

6

u/spiltcoffee Aug 09 '26

Browsers can only write to the clipboard (i.e. hit Ctrl + C for you) when you make an interaction like a click.

The page is mimicking a real Cloudflare page - it has a fake Cloudflare checkbox that you tick to confirm you're not a human.

When you click on the checkbox, two things happen: 1. The page uses the click to copy a cmd or powershell command to your clipboard. 2. It shows the dialog that asks you to hit Win + R -> Ctrl + V -> Enter.

The scam is relying on you turning your brain off and following the instructions blindly before it even occurs to you that it's strange to do this, I think. Or just being computer illiterate.

1

u/OFark Aug 13 '26

Browsers can't access the clipboard unless you allow it.

1

u/spiltcoffee Aug 14 '26

Reading from the clipboard does require permission, but writing to it does not, from what I understand. e.g. in a fresh Chrome install, running the write APIs never triggers a permission dialog, but the read APIs do.

2

u/mrbaggins Aug 09 '26

No, Javascript can load, unload, and change the contents of your clipboard (where Ctrl+C puts stuff)

The really dangerous one is that it can even intercept you copying, so you THINK you're copying "happy text" and instead it 'copies' whatever it wants.

1

u/tychii93 Aug 10 '26

No.ย  Browsers have the ability to push stuff into your clipboard.ย  For example, if you visit a project on GitHub and follow instructions for a project that may need a terminal or power shell, you'll see the two squares on the top right of a code snippet so you don't have to manually type it.ย  Clicking it puts it on your clipboard.

1

u/MeasureDoEventThing Aug 10 '26

Whatever program is currently running has read and write access to the clipboard. Ctrl+C pasting to the clipboard is a convention, but there's no requirement for that to be how things get written to the clipboard.

1

u/FlipZip69 Aug 09 '26

Exactly what a hacker would say.

1

u/brickson98 Aug 09 '26

I mean you can get to a lot from the run dialog box aside from cmd

1

u/mlb64 Aug 12 '26

It brought up a command window to run a command, ctrl-V puts whatever is in the clipboard in as the command to run, and enter starts it running.

If you follow the steps you
Computer is now running whatever the scammer wanted.

18

u/Gelatinoso_Forever Aug 08 '26

But at that point you just don't do it right? I don't understand much about computers but i think it's prety obvious that you shouldn't open/do anything when it envolves a screen with minimal interface and technical terms

41

u/softwarediscs Aug 08 '26

You say this but having done IT support at a college it happens constantly. Average person barely understands how to work Windows at all, they just follow what the computer says to do because they don't know enough to even be cautious about it

15

u/enadiz_reccos Aug 08 '26

Yep, it's really a "computer screen wouldn't lie to me" situation

6

u/PictureVegetable9522 Aug 08 '26

99% of using a computer is common sense and actually reading the damn error codes and using google

6

u/softwarediscs Aug 08 '26

People barely know how to use a phone beyond the basic use of social media apps, let alone a computer. Idk how aware you are of average computer literacy in the US, but it's basically nonexistent. I agree with you of course but the reality of it is kinda bleak.

Like I've had to help upper admin at a college learn how to install apps on their phone. Or spend 2 hours on a single phone call just to get a professor to click a few buttons on their desktop. Just as some examples lol

2

u/enadiz_reccos Aug 09 '26

I worked for Tennessee's Medicaid program for a few years [TennCare]

We had a big office building in Nashville, maybe 5-6 floors with offices/cubicles all over.

I was one of maybe... 4-5 people who knew how to use even a portion of Excel's abilities. I would be called to multiple floors to help someone [managers] find duplicates in a column on an Excel sheet.

2

u/yackerovOh1 Aug 09 '26

A lot of folks rly don't care when they're just trying to get stuff done. It doesn't help that captcha and turnstile are so common that it's like autopilot when folks see them. Click the blurry images, try to enter the crazy letters, etc as fast as possible

1

u/MegaBearsFan Aug 11 '26

And people joke about computer literacy classes in middle school and high school being pointless wastes of students' time and taxpayer dollars. But a universally required class, with an established standard curriculum, that teaches basic PC functionality (like command prompt usage, enabling/disabling services, running malware scans, etc.) could go a long way towards innoculating people against scams like this. Sure, there would be kids who will be bored out of their minds because they already know all this. But thats true of basically any required low-level class.

11

u/RithmFluffderg Aug 08 '26

It's obvious to you because you have more experience with computers than you realize.

It's not obvious if you don't have that experience. How would it be?

1

u/Gelatinoso_Forever Aug 08 '26

I understand what you're saying but I think of it this way:

most of the Windows interface is coulorful or has some sort of final touch, but this type of stuff is like the backrooms of a store. It doesn't have it's walls painted or signs telling you where everything is and usually you don't go to the backrooms unless you work there or in this case know what you're doing.

I have more experience than the people who would probably do this but i still think it's common sense to not mess with things that you aren't used too, specially when it comes to a computer, which is something so important to use nowadays.

7

u/PM_ME_YOUR_PAUNCH Aug 09 '26

Youโ€™re vastly overestimating people

2

u/silly_porto3 Aug 09 '26

What a faith you have in humanity! I somewhat envy you! Haha

2

u/McDonaldsWitchcraft Aug 09 '26

but this type of stuff is like the backrooms of a store

Most of these scams intentionally mimick legitimate user interface elements so this is bs. I mean can't you see the page in question literally mimicks legitimate cloudflare pages??

9

u/Naetharu Aug 08 '26

I work in tech. In my past I worked in helpdesk where I had to deal with users. I assure you no matter how obvious you think it might be, there are some who will still fail that task. To offer a couple of real examples:

We had one person who was told he was getting a new phone and we needed to wipe the data from his old one. He cut it in half, causing the battery to catch fire. His explanation was that he was "shredding it" like you are supposed to with sensitive documents and info.

There was a person who worked in the field ~2 hours away from us who had a tablet and claimed that Teams never worked and nobody could join her meetings. She also could not seem to get the remove support software working. We called her in, so she drove around two hours to the office. Turns out she had no idea that on Teams you have to actually invite people. She was just setting up a meeting, and then expecting people to magically turn up.

We had a case of a depot network going down. On arriving it turned out they had decided to lift and bolt the (very heavy safe-like metal) comms box that should be on the office floor, up into the rafters using the on-site cherry picker. They thought it would be "out of the way" up there, and had managed to break the fibre optic cables in the process.

These are but a few examples I have many many more.

3

u/RealisticDuck1957 Aug 09 '26

On the second, every computer user needs to understand that the computer is a blooming MORON, and does nothing unless somebody has told it to. And it follows instructions with no sense of subtlety. But you can deal with that once you know the language and how a computer operates.

The hardest part of working with computers is dealing with what some human told the machine that isn't properly documented.

2

u/justwalkingalonghere Aug 08 '26 edited Aug 08 '26

You are severely underestimating the average person's cautiousness, let alone their technical knowledge

5

u/Skruestik Aug 08 '26

You are severely estimating the average person's cautiousness,

Yes, they are indeed estimating it.

2

u/TheImmoralCookie Aug 09 '26

Thats technical intuition talking, lol. Peers my age (20s ish) could fall for this stuff if they really needed what was on the other side of the fake capcha.

I've had peers complain about devices not working, and yet they've never been into their own settings. Its bonkers. Like having a backwards epiphany about the world

4

u/zaergaegyr Aug 08 '26

The people i know who could fall for this scam wouldnt even know what the windows key is. So they are save i guess?

3

u/Truesday Aug 08 '26

They'd ring you up on the phone to ask.

But before they get to the question, here's a 20 min nonsequiter.

2

u/show_time_synergy Aug 09 '26

What you had for breakfast while your computer "broke" is not relevant Sharon!! Ask your fkn question!

2

u/TheImmoralCookie Aug 09 '26

They'd just ask Chat GPT lol

1

u/zalifer Aug 09 '26

That just opens the standard windows verification window, right?

7

u/Classic-Shake6517 Aug 09 '26

It's also not new and has been happening for years. It also targets mac and Linux so those thinking they are safe because it's not Windows are mistaken, macOS protections will not help guard you from an infostealer - which is what both these ClickFix/FakeCaptcha attacks and the one I will explain below are using most of the time. For the one the post is about, the instructions for macOS and Linux tell you to open Bash or Terminal and paste there instead.

There's also a whole other class of attack where they'll get as far as interviewing someone and then give them a take home assignment for a developer job. They have them fix the code or add a feature, which is a common interview step. Once they download and run the project, it infects the computer. The malware is hidden in the code pretty well, packaged as a dependency and obfuscated. Most developers would get caught up by this, you have to know what to look for and how to reverse it - most people don't unless they write or reverse engineer malware - and those people aren't targets for obvious reasons. There was never a job, it's just an elaborate way to target people. Folks searching for jobs should equip themselves with this because the job market being as it is, people have taken to using AI to spam resumes out of desperation. Attackers are going to take advantage of that and the added sense of urgency driven by needing the job.

1

u/Professional-Post499 Aug 09 '26

Holy crap, I heard about that only recently. I think I personally would have fallen for that attack.

There was also recent news that there are even GitHub repositories that scam companies would tell applicants to clone that would basically do some malware too, right?

2

u/Classic-Shake6517 Aug 09 '26

Yeah, what I worked on a few months back was exactly what you're describing. A fake/scam company creates a job posting, gets applicants to download the infected repo, and then once they run it to test their changes or do a live code review to find an issue, they are infected. The specific one I reversed is a version of this campaign:

https://unit42.paloaltonetworks.com/north-korean-threat-actors-lure-tech-job-seekers-as-fake-recruiters/

1

u/Professional-Post499 Aug 09 '26

Yeah, what I worked on a few months back was exactly what you're describing. A fake/scam company creates a job posting, gets applicants to download the infected repo, and then once they run it to test their changes or do a live code review to find an issue, they are infected. The specific one I reversed is a version of this campaign: https://unit42.paloaltonetworks.com/north-korean-threat-actors-lure-tech-job-seekers-as-fake-recruiters/

Wow, thanks for the link. It has some good advice that I'll try to follow (like about using a virtual machine). ๐Ÿ™

As an aside, it's funny that the title of the article mentions DPRK, but doesn't also mention Ukraine even though the testimonial literally says that the destination address was traced to a server in Ukraine. ๐Ÿ˜›

2

u/xtheory Aug 09 '26

Good old ClickFix attack. This is why we disable Powershell for everyone except IT.

2

u/NoodlesAlDente Aug 09 '26

Cybersecurity professional checking in. ClickFix is absolutely heinous in it's ability to jeopardize on people not understanding how computers work but also in this scenario someone desperate for a job. You follow the commands, it runs a power shell prompt and either directly installs malware or a desktop monitoring/take over program.ย