Skip to main content
  1. Home
  2. Computing
  3. News

Double-check that job posting — hackers are spreading malware through them

Add as a preferred source on Google

A new phishing scam has surfaced that is showing how sophisticated bad actors are becoming in tricking unsuspecting victims into giving up their personal information.

The latest cyberattack is centered around the job listing website, Indeed. Hackers send out an email spoofing an employment opportunity from the website. Once you click the link, it will send you to a Microsoft 365 login page to enter your credentials. From here you’re not suspecting anything unscrupulous, but the next time you attempt to log into your Microsoft 365 account, you will find that not only are you getting an error message that the information is incorrect, but that your account is no longer available.

A hacker typing on an Apple MacBook laptop while holding a phone. Both devices show code on their screens.
Sora Shimazaki / Pexels

Researchers at Menlo Security have observed this phishing scam, which is being targeted at U.S. executives in industries including electronic manufacturing, banking and finance, real estate, insurance, and property management, according to Bleeping Computer.

Recommended Videos

The cyberattack has been so seamless it has been able to evade multifactor authentication on Microsoft 365 accounts through a method called cookie stealing. This tactic is used to swipe the cookies from well-known websites and mimic their designs. By hacking recent web sessions of programs that are not commonly refreshed, bad actors that replicate pages can look identical to pages of common websites. Cookie stealing was also developed as a bypass for multi-factor authentication. If you have the security feature set up on your account, you would likely input it yourself, having visually deemed the website to be trustworthy.

Researchers began noticing cookie stealing attacks in 2022, targeting several major brands, including Google Chrome, Amazon Web Services (AWS), Azure, Slack, and Electronic Arts.

The hackers in this case used a platform called EvilProxy to execute their cookie stealing and fashion a page that looks like an authentic Microsoft login page. Multifactor authentication is commonplace for Microsoft 365 so users will have some form set up.

The addition of the Indeed email makes this phishing scam especially complex because opening the link triggers an open redirect, which is a weakness that allows the bad actor to direct you to their nefarious website after clicking on a seemingly legitimate link.

This isn’t the only phishing scam plaguing Microsoft services in recent times. Last month, for example, a team of hackers was able to infiltrate Microsoft Teams to execute a phishing scam called “DarkGate Loader.” The scheme centers on a bogus Teams message about “changes to the vacation schedule,” but contains intricate hidden malware when downloaded. Cybersecurity researchers uncovered that hackers were able to access Teams through compromised Office 365 accounts and even found the unsecured email addresses they were able to take over.

Ongoing spam and cybercrime have prompted email providers, including Gmail and Yahoo to set into place requirements for bulk senders as security measures. These requirements include email authentication, the ability to easily unsubscribe, and email assurance, and will be set in place starting February 1, 2024. Google said many of the requirements largely play as basic email hygiene but are being set forth with the aim of making it an industry standard.

Fionna Agomuoh
Fionna Agomuoh is a Computing Writer at Digital Trends. She covers a range of topics in the computing space, including…
Microsoft wants Copilot to answer all your health-related questions and store your medical records
Copilot Health is Microsoft's most personal AI feature yet. It is built with 250 physicians, and explicitly designed not to replace your doctor.
Page, Text, Business Card

Copilot Health is now in preview, and Microsoft’s ambition for it is clear, an AI assistant that knows your health history, understands your fitness data, and can help you make sense of your medical records, all in one place. 

Copilot Health is a dedicated space within the Copilot chatbot at copilot.microsoft.com/health where you can get answers to your health-related questions. 

Read more
MSI’s Triple Mode OLED monitor is a Computex showstopper and my eyes genuinely can’t wait for it
MSI's Triple Mode OLED raises the bar for gaming monitors at Computex 2026.
Computer Hardware, Electronics, Hardware

Dual-mode gaming monitors have been around long enough that the novelty has worn off. MSI has decided that two modes simply aren't enough and has unveiled the MPG OLED 322URDX36 ahead of Computex 2026.

It is the world's first Triple Mode gaming monitor, and if the execution is as good as it sounds, it could be one of the few gaming monitors that I’d be genuinely interested in. 

Read more
Dell doubles down on 5G cellular connectivity for its premium business laptops in the US
The new launch is Dell’s clearest statement that 5G cellular connectivity belongs in every premium business laptop, not just enterprise niches.
Computer, Electronics, Laptop

Dell released a wave of new laptops on May 29, 2026, just four days before Computex 2026 opens in Taipei on June 2. Amid a loaded spec sheet, nearly every flagship model in the new batch offers optional 5G cellular connectivity. 

While the capability has traditionally been reserved for ultraportable or enterprise-grade devices, Dell is signalling that always-connected laptops are no longer a niche requirement. 

Read more