Hackers are using fake job interviews to load applicants’ PCs with a password-stealing Trojan

Cybersecurity researchers at Dr.Web have identified a growing threat targeting job seekers: a Trojan virus called “JobStealer” distributed through fraudulent video conference interviews. Hackers contact unemployed individuals with job offers and invite them to participate in interviews via what appears to be legitimate video conferencing software. When users download the purported conferencing application, they unknowingly install malware capable of stealing passwords and other sensitive credentials.

The scam is designed with notable sophistication. The fake conferencing websites closely mimic legitimate platforms, with some campaigns directly spoofing real services like Webex to establish credibility. Attackers further enhance the deception by connecting compromised social media accounts to the fake job postings and interview invitations, making the opportunity appear authentic to unsuspecting candidates.

This social engineering approach exploits a particularly vulnerable demographic: people actively seeking employment who are motivated to participate in interview processes. The attack chain is simple but effective—initial contact through job-related channels, a seemingly legitimate interview invitation, and a software download that users believe is necessary to participate.

Sources