This massive new spoofing campaign is targeting job seekers, so watch out
A new worldwide spoofing campaign has been discovered, and it is thought to have extorted over $100 million from its victims already.
Researchers at security firm CloudSEK say the scam involves the impersonation of over a thousand companies, and is affecting over 100,000 people across more than 50 countries.
They also say that the threat actors behind the campaign are highly skilled and have created over 6,000 fake websites that impersonate popular brands, and hundreds of WhatsApp and Telegram handles have been employed to lure victims.
Webwyrm
Dubbed Webwyrm, the researchers note that the campaign has likely been active since late 2022, but gathered momentum early this year as the threat actors evolved their tactics.
The impersonated brands span over 10 industries, with the threat actors offering fake job roles to unsuspecting victims via social media, especially encrypted messaging service WhatsApp. CloudSEK’s report also suggests that the threat actors may be “leveraging data from recruitment portals to tailor their schemes.”
The fake employment offer typically offers a salary of between $1200-$1500 on average, with commissions based on how much “”work” the victim does. The job is to complete between 2-3 sets of tasks per day, with 40 tasks per set.
Once the task is complete, the money will be taken from the victim’s account and then redeposited along with the commission. The money is deposited in cryptocurrency exchange platforms and converted into USDT, a stablecoin pegged to the US dollar.
The victim is told to create an account on a fake website impersonating a well-known brand. There are also combo tasks, which require double the investment from the victim and have to be completed in streaks, otherwise the victim cannot withdraw their pay.
But the streak never completes, and victims invest more and more in a vain attempt to complete it. Eventually, the threat actors freeze them out of their account. But in an effort to convince victims that its not a scam, they are directed to group chats where other “workers” post about how much money they have made.
The types of companies that are impersonated include digital marketing and advertising services. Most of the impersonated companies are US based, with Indian, UK and Singapore firms also being popular choices.
MORE FROM TECHRADAR PRO
A new worldwide spoofing campaign has been discovered, and it is thought to have extorted over $100 million from its victims already. Researchers at security firm CloudSEK say the scam involves the impersonation of over a thousand companies, and is affecting over 100,000 people across more than 50 countries. They…
Recent Posts
- Apple begins requiring age verification for App Store use in Texas
- Apple is bringing age verification to Texas this week
- How to watch NBA Finals 2026: Free streams, schedule, TV channels for New York Knicks vs San Antonio Spurs
- WiiM expands its whole-home ecosystem with a new soundbar
- You can make the hyper-violence in Marvel’s Wolverine more PG-13, if you want to
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023