Don’t Fall for the Fake Corsair Job Offer Infecting PCs
Written by: Thomas Orsolya
Published on:
A new phishing campaign is targeting social media managers with fake job offers pretending to be from computer hardware company Corsair. This scam aims to infect victims with information-stealing malware like DarkGate and RedLine by having them download infected files attached to the fake job offers.
Cybersecurity firm WithSecure uncovered this campaign and linked it to Vietnamese cybercriminal groups behind previous ‘Ducktail’ campaigns first detected in 2022. These campaigns try to steal valuable Facebook business accounts that can be misused for malicious advertising or sold to other hackers.
This detailed guide will explain how the Corsair job scam works, help you recognize the tactics used, and provide steps to take if you downloaded any suspicious files.
This article contains:
Overview of the Fake Corsair Job Offer Scam
The threat actors behind this scam have been targeting potential victims mainly in the United States, United Kingdom, and India who list social media management in their LinkedIn profiles. The lure is a fake job posting for a Facebook Ads Specialist role at Corsair delivered via LinkedIn messages and posts.
The goal is to trick targets into downloading ZIP archives containing malware-laden PDFs, Word documents, or text files. WithSecure’s analysis of the metadata inside these malicious archives points to the RedLine and DarkGate information-stealing malware being distributed currently.
Once installed on a victim’s computer, this malware can:
Steal sensitive data like login credentials, financial information, screenshots, browser histories, etc.
Gather system information like installed software, hardware devices, and configurations.
Record keystrokes to grab passwords, messages, and other confidential data.
Take remote control of the infected computer.
Spread laterally in a network by exploiting vulnerabilities.
The stolen data allows the attackers to gain access to the victim’s social media accounts and business assets. Compromised Facebook advertising accounts, in particular, can earn the hackers money through malicious ads or reselling the assets.
Step-by-Step Breakdown of the Fake Job Offer Scam Process
The fake Corsair job offer scam is designed to manipulate busy professionals into hastily downloading attachments containing malware. Here is how the scam typically progresses:
1. Initial Contact Over LinkedIn
The first contact is initiated via LinkedIn messages or fake job posts. The attackers create convincing profiles often posing as Corsair HR representatives or recruiters at staffing agencies.
The messages will mention an open position for a Facebook Ads Specialist role at Corsair that fits the target’s experience. A brief role description and enticing salary figure are given to lure them in.
2. Request to Download Job Details
The next step sees the scammer direct the target to download full job details from a Google Drive or Dropbox link:
“Please download the attached document that outlines the job description, responsibilities, and salary information for the Facebook Ads Specialist position. You can find all the details here: g2.by/corsair-JD”
The Google Drive or Dropbox link redirects to a ZIP archive download like Salary and new products.8.4.zip.
3. Malware Hidden in Job Details Files
This ZIP archive contains malware-laden files like:
Job Description of Corsair.docx – A Word doc with an embedded VBS script
Salary and new products.txt – Benign text file
PDF Salary and Products.pdf – Malicious PDF
The Word document contains macros or VBS scripts that will execute once opened to download additional malware components. The PDF likely exploits an Adobe Reader vulnerability to install malware.
4. Malware Installation & Activity
Once executed, the VBS script copies and renames curl.exe to initiate the next stage infection. It downloads and executes autoit3.exe along with an obfuscated AutoIt3 script.
This script then constructs the DarkGate malware using code strings present in the script itself. The malware has modules to:
Steal browser data, credentials, screenshots, etc.
Record keystrokes to grab sensitive info entered by the user
Remotely take control of the infected system
Spread laterally to other computers on the network
Within 30 seconds of infection, DarkGate attempts to disable security software to evade detection. The attackers likely have full access to the compromised computer at this stage.
5. Results for the Attackers
With their malware successfully installed on the target’s computer, the attackers can now steal passwords, business accounts, financial information, and other valuable data.
Access to social media and advertising accounts are a prime target. The hackers can misuse or resell compromised Facebook business assets. They can also leverage corporate email accounts for further social engineering attacks.
This gives the threat actors valuable data, pivot points into corporate networks, and potential monetary gain.
What to Do If You Downloaded Suspicious Files
If you downloaded and opened any suspicious Word docs, PDFs, or other files from unknown contacts on LinkedIn, follow these steps to secure your systems:
1. Disconnect From the Internet and Network
Immediately unplug your computer’s internet connection and disconnect from any office networks. This prevents malware from communicating with command servers or spreading.
2. Scan for Malware
Install quality antivirus software like Malwarebytes or ESET if you don’t have any. Perform a full system scan to detect and remove any potential malware.
3. Change All Passwords
Assume all your passwords have been compromised. Carefully change passwords for email, social media, financial services, and work software accounts. Avoid reusing any old passwords. Enable two-factor authentication wherever possible.
4. Contact Corsair and LinkedIn
Notify Corsair that cybercriminals are posing as recruiters and using fake job offers in their name. Also contact LinkedIn to report the fake accounts spreading malware.
5. Check Accounts for Suspicious Activity
Carefully check your social media, payment accounts, and email accounts for any unauthorized access, posts, or transactions. Report any strange activity to the providers. Monitor account activity closely over the next few months.
6. Wipe and Restore the Infected Device
The safest option is to wipe the infected hardware completely and reinstall the operating system and software from scratch. Restore cleaned files and data only from known good backups. If this is not feasible, at least follow steps 1-5.
7. Inform Your IT Department
If you were using a work device or credentials, alert your IT security team. They can assess risks to the broader organization, scan network activity, and take steps to prevent a wider breach.
Stay vigilant against potential follow-up attacks aimed at your employer or clients. The attackers may leverage any compromised accounts or data for additional phishing attempts, client email spoofing, or other social engineering.
Is Your Device Infected? Check for Malware
If your device is running slowly or acting suspicious, it may be infected with malware. Malwarebytes Anti-Malware Free is a great option for scanning your device and detecting potential malware or viruses. The free version can efficiently check for and remove many common infections.
Malwarebytes can run on Windows, Mac, and Android devices. Depending on which operating system is installed on the device you’re trying to run a Malwarebytes scan, please click on the tab below and follow the displayed steps.
Malwarebytes For WindowsMalwarebytes For MacMalwarebytes For Android
Scan your computer with Malwarebytes for Windows to remove malware
Malwarebytes stands out as one of the leading and widely-used anti-malware solutions for Windows, and for good reason. It effectively eradicates various types of malware that other programs often overlook, all at no cost to you. When it comes to disinfecting an infected device, Malwarebytes has consistently been a free and indispensable tool in the battle against malware. We highly recommend it for maintaining a clean and secure system.
Download Malwarebytes for Windows
You can download Malwarebytes by clicking the link below.
After the download is complete, locate the MBSetup file, typically found in your Downloads folder. Double-click on the MBSetup file to begin the installation of Malwarebytes on your computer. If a User Account Control pop-up appears, click “Yes” to continue the Malwarebytes installation.
Follow the On-Screen Prompts to Install Malwarebytes
When the Malwarebytes installation begins, the setup wizard will guide you through the process.
You’ll first be prompted to choose the type of computer you’re installing the program on—select either “Personal Computer” or “Work Computer” as appropriate, then click on Next.
Malwarebytes will now begin the installation process on your device.
When the Malwarebytes installation is complete, the program will automatically open to the “Welcome to Malwarebytes” screen.
On the final screen, simply click on the Open Malwarebytes option to start the program.
Enable “Rootkit scanning”.
Malwarebytes Anti-Malware will now start, and you will see the main screen as shown below. To maximize Malwarebytes’ ability to detect malware and unwanted programs, we need to enable rootkit scanning. Click on the “Settings” gear icon located on the left of the screen to access the general settings section.
In the settings menu, enable the “Scan for rootkits” option by clicking the toggle switch until it turns blue.
Now that you have enabled rootkit scanning, click on the “Dashboard” button in the left pane to get back to the main screen.
Perform a Scan with Malwarebytes.
To start a scan, click the Scan button. Malwarebytes will automatically update its antivirus database and begin scanning your computer for malicious programs.
Wait for the Malwarebytes scan to complete.
Malwarebytes will now scan your computer for browser hijackers and other malicious programs. This process can take a few minutes, so we suggest you do something else and periodically check the status of the scan to see when it is finished.
Quarantine detected malware
Once the Malwarebytes scan is complete, it will display a list of detected malware, adware, and potentially unwanted programs. To effectively remove these threats, click the “Quarantine” button.
Malwarebytes will now delete all of the files and registry keys and add them to the program’s quarantine.
Restart your computer.
When removing files, Malwarebytes may require a reboot to fully eliminate some threats. If you see a message indicating that a reboot is needed, please allow it. Once your computer has restarted and you are logged back in, you can continue with the remaining steps.
Your computer should now be free of trojans, adware, browser hijackers, and other malware.
If your current antivirus allowed this malicious program on your computer, you may want to consider purchasing Malwarebytes Premium to protect against these types of threats in the future. If you are still having problems with your computer after completing these instructions, then please follow one of the steps:
Scan your computer with Malwarebytes for Mac to remove malware
Malwarebytes for Mac is an on-demand scanner that can destroy many types of malware that other software tends to miss without costing you absolutely anything. When it comes to cleaning up an infected device, Malwarebytes has always been free, and we recommend it as an essential tool in the fight against malware.
Download Malwarebytes for Mac.
You can download Malwarebytes for Mac by clicking the link below.
When Malwarebytes has finished downloading, double-click on the setup file to install Malwarebytes on your computer. In most cases, downloaded files are saved to the Downloads folder.
Follow the on-screen prompts to install Malwarebytes.
When the Malwarebytes installation begins, you will see the Malwarebytes for Mac Installer which will guide you through the installation process. Click “Continue“, then keep following the prompts to continue with the installation process.
When your Malwarebytes installation completes, the program opens to the Welcome to Malwarebytes screen. Click the “Get started” button.
Select “Personal Computer” or “Work Computer”.
The Malwarebytes Welcome screen will first ask you what type of computer are you installing this program, click either Personal Computer or Work Computer.
Click on “Scan”.
To scan your computer with Malwarebytes, click on the “Scan” button. Malwarebytes for Mac will automatically update the antivirus database and start scanning your computer for malware.
Wait for the Malwarebytes scan to complete.
Malwarebytes will scan your computer for adware, browser hijackers, and other malicious programs. This process can take a few minutes, so we suggest you do something else and periodically check on the status of the scan to see when it is finished.
Click on “Quarantine”.
When the scan has been completed, you will be presented with a screen showing the malware infections that Malwarebytes has detected. To remove the malware that Malwarebytes has found, click on the “Quarantine” button.
Restart computer.
Malwarebytes will now remove all the malicious files that it has found. To complete the malware removal process, Malwarebytes may ask you to restart your computer.
Your Mac should now be free of adware, browser hijackers, and other malware.
If your current antivirus allowed a malicious program on your computer, you might want to consider purchasing the full-featured version of Malwarebytes Anti-Malware to protect against these types of threats in the future. If you are still experiencing problems while trying to remove a malicious program from your computer, please ask for help in our Mac Malware Removal Help & Support forum.
Scan your phone with Malwarebytes for Android to remove malware
Malwarebytes for Android automatically detects and removes dangerous threats like malware and ransomware so you don’t have to worry about your most-used device being compromised. Aggressive detection of adware and potentially unwanted programs keeps your Android phone or tablet running smooth.
Download Malwarebytes for Android.
You can download Malwarebytes for Android by clicking the link below.
In the Google Play Store, tap “Install” to install Malwarebytes for Android on your device.
When the installation process has finished, tap “Open” to begin using Malwarebytes for Android. You can also open Malwarebytes by tapping on its icon in your phone menu or home screen.
Follow the on-screen prompts to complete the setup process
When Malwarebytes will open, you will see the Malwarebytes Setup Wizard which will guide you through a series of permissions and other setup options. This is the first of two screens that explain the difference between the Premium and Free versions. Swipe this screen to continue. Tap on “Got it” to proceed to the next step. Malwarebytes for Android will now ask for a set of permissions that are required to scan your device and protect it from malware. Tap on “Give permission” to continue. Tap on “Allow” to permit Malwarebytes to access the files on your phone.
Update database and run a scan with Malwarebytes for Android
You will now be prompted to update the Malwarebytes database and run a full system scan.
Click on “Update database” to update the Malwarebytes for Android definitions to the latest version, then click on “Run full scan” to perform a system scan.
Wait for the Malwarebytes scan to complete.
Malwarebytes will now start scanning your phone for adware and other malicious apps. This process can take a few minutes, so we suggest you do something else and periodically check on the status of the scan to see when it is finished.
Click on “Remove Selected”.
When the scan has been completed, you will be presented with a screen showing the malware infections that Malwarebytes for Android has detected. To remove the malicious apps that Malwarebytes has found, tap on the “Remove Selected” button.
Restart your phone.
Malwarebytes for Android will now remove all the malicious apps that it has found. To complete the malware removal process, Malwarebytes may ask you to restart your device.
Your phone should now be free of adware, browser hijackers, and other malware.
If your current antivirus allowed a malicious app on your phone, you may want to consider purchasing the full-featured version of Malwarebytes to protect against these types of threats in the future. If you are still having problems with your phone after completing these instructions, then please follow one of the steps:
Restore your phone to factory settings by going to Settings > General management > Reset > Factory data reset.
Frequently Asked Questions About the Fake Corsair Job Offer Scam
What is the fake Corsair job offer scam?
This is a phishing campaign where attackers pretend to recruit for Corsair and send fake job offers containing malware to social media managers and ad account pros. The goal is to infect them with info-stealing malware.
How does the scam work?
It starts with a message on LinkedIn about an appealing role at Corsair. You get directed to download a ZIP file with job details that hides malware-laden PDFs and Word docs. If you open these, it will infect your computer.
What malware is being distributed?
Researchers found evidence of DarkGate and RedLine stealer malware in the phishing attachments. These steal data like passwords, screenshots, credentials, and browser history.
What’s the end goal of this scam?
The attackers want to hijack valuable social media advertising accounts, especially Facebook Business accounts. Compromised accounts can be misused or resold by the hackers.
Why target social media managers?
These roles likely have access to corporate social media accounts. Stealing just 1-2 Facebook ad accounts gives the hackers plenty of money-making potential.
How do I recognize this scam?
Be suspicious of unsolicited LinkedIn messages about vague Corsair roles that urgently direct you to download job description files from Google Drive or Dropbox.
What should I do if I downloaded suspicious files?
Disconnect your device from internet/network immediately. Scan for malware, reset passwords, contact Corsair/LinkedIn, monitor accounts closely for unauthorized activity.
How can I avoid falling for this scam?
Never download files from strangers. Always verify LinkedIn contacts and job offers directly on company sites before engaging. Use security tools to scan links and attachments.
Who is behind this scam campaign?
Researchers attribute it to Vietnamese cybercriminal groups that have been running ‘Ducktail’ campaigns focused on stealing social media assets since last year.
The Bottom Line
The fake Corsair job offer scam demonstrates how far cybercriminals will go to compromise corporate assets including social media advertising accounts. The carefully crafted social engineering lures in this campaign play on people’s desire for career growth and urgency to apply for a hot new role.
But stopping to verify the source, double-check linked URLs, and scan attachments could have prevented infection. The lure of a hot new job opportunity cost the targets their credentials, data, and access in the end.
Defending against these threats means adopting a careful, suspicious approach to unsolicited contacts and job offers. Scrutinize every link and attachment, no matter how appealing the message seems. Stick to visiting job sites directly rather than clicking embedded links.
Investing in stronger email and endpoint security solutions also adds multiple layers of protection. Combining vigilance with the right mix of defenses can help companies safeguard their social media assets and business accounts from compromise.
How to Stay Safe Online
Here are 10 basic security tips to help you avoid malware and protect your device:
Use a good antivirus and keep it up-to-date.
It's essential to use a good quality antivirus and keep it up-to-date to stay ahead of the latest cyber threats. We are huge fans of Malwarebytes Premium and use it on all of our devices, including Windows and Mac computers as well as our mobile devices. Malwarebytes sits beside your traditional antivirus, filling in any gaps in its defenses, and providing extra protection against sneakier security threats.
Keep software and operating systems up-to-date.
Keep your operating system and apps up to date. Whenever an update is released for your device, download and install it right away. These updates often include security fixes, vulnerability patches, and other necessary maintenance.
Be careful when installing programs and apps.
Pay close attention to installation screens and license agreements when installing software. Custom or advanced installation options will often disclose any third-party software that is also being installed. Take great care in every stage of the process and make sure you know what it is you're agreeing to before you click "Next."
Install an ad blocker.
Use a browser-based content blocker, like AdGuard. Content blockers help stop malicious ads, Trojans, phishing, and other undesirable content that an antivirus product alone may not stop.
Be careful what you download.
A top goal of cybercriminals is to trick you into downloading malware—programs or apps that carry malware or try to steal information. This malware can be disguised as an app: anything from a popular game to something that checks traffic or the weather.
Be alert for people trying to trick you.
Whether it's your email, phone, messenger, or other applications, always be alert and on guard for someone trying to trick you into clicking on links or replying to messages. Remember that it's easy to spoof phone numbers, so a familiar name or number doesn't make messages more trustworthy.
Back up your data.
Back up your data frequently and check that your backup data can be restored. You can do this manually on an external HDD/USB stick, or automatically using backup software. This is also the best way to counter ransomware. Never connect the backup drive to a computer if you suspect that the computer is infected with malware.
Choose strong passwords.
Use strong and unique passwords for each of your accounts. Avoid using personal information or easily guessable words in your passwords. Enable two-factor authentication (2FA) on your accounts whenever possible.
Be careful where you click.
Be cautious when clicking on links or downloading attachments from unknown sources. These could potentially contain malware or phishing scams.
Don't use pirated software.
Avoid using Peer-to-Peer (P2P) file-sharing programs, keygens, cracks, and other pirated software that can often compromise your data, privacy, or both.
To avoid potential dangers on the internet, it's important to follow these 10 basic safety rules. By doing so, you can protect yourself from many of the unpleasant surprises that can arise when using the web.
Meet Thomas Orsolya
Thomas is an expert at uncovering scams and providing in-depth reporting on cyber threats and online fraud. As an editor, he is dedicated to keeping readers informed on the latest developments in cybersecurity and tech.