❌

Normal view

Fake Google Security Team ad says 'no script reading' in voice phishing - then prints the script

25 September 2026 at 19:13
Yes, criminals have job listings too. A Telegram user recruiting callers to work in an apparent Google Security Team voice-phishing scam told applicants that they weren’t allowed to read from scripts – in the same ad that also included the exact script they had to read during these scam calls. This and other true-crime tales of criminals making fools of themselves appear in the latest installment of the Trellix Advanced Research Center’s Dark Web Roast, which uses memes and mockery to troll criminals on the dark web. It also acknowledges: “While these incidents are genuinely amusing, they represent real criminal activities causing significant harm.” One of these incidents from August involves a Telegram user identified by Trellix as Derian (@crɑick) who posted an ad in the UK Fraudsters Telegram channel. “Hiring - Female/Male Mail Callers,” the advertisement said, seeking “USA/CA (white sounding)” applicants and, in bold, “NO SCRIPT READING.” The ad then proceeded to print the exact script the callers would read: “Good afternoon, this is [name] reaching you on behalf of the Google Account Security Team on a recorded line. Am I speaking with Larry Boyles?” The Trellix threat-intel analysts note that the “‘recorded line’ flourish is a nice touch, because nothing says legitimacy like a fraudster cosplaying compliance theatre. The pretexting playbook is depressingly effective, but the recruiter’s QA process is roughly as robust as the fake Google team it impersonates.” Burn, baby, burn. The Register previously spoke with Trellix VP of threat intelligence strategy John Fokker about the Dark Web Roast, and he said the idea came from a desire to take an "almost psyops" approach to covering the criminal underground. "We don't want to glorify them, what's the opposite we can do? We're going to roast them," Fokker told us during a conversation at RSAC. "I'm trying to spark a debate, or a healthy conversation, about what we can do as an industry," he said. "Everybody's glorifying threat actors, and that's not helping our customers or organizations. These are just individuals, they just use computers, and they just want to steal your data and make money. They're not mythical. They don't have superpowers." The FBI’s Internet Crime Complaint Center (IC3) recently reported its most damaging year for internet scams, with 2025’s data pegging reported losses at $20.87 billion, and English-language social engineering is among the most in-demand skill sets on underground forums. One report by threat detection and response firm ReliaQuest found the number of job advertisements posted on criminal marketplaces mentioning this particular talent more than doubled between 2024 and 2025. Plus, according to Google, voice phishing surged last year to become the second most common method used by cybercriminals to gain initial access to their victims' IT estate – and the No. 1 tactic used when breaking into cloud environments. So when these criminals do dumb things, we’re happy to see Fokker’s team call them out.®

Crooks use fake desktop apps to fool HR staff into giving them remote access

25 September 2026 at 17:29
You work in your company's human resources department and use HR software to check employee information, benefits, and payroll. So, when you see a downloadable Windows version promising a faster alternative to the usual web interface, you grab it. Unfortunately, the app isn't what it claims to be. Instead, it silently installs ConnectWise's legitimate ScreenConnect software, giving the operator persistent remote access to your PC. Cybersecurity outfit Allure Security reported the discovery of the campaign Thursday, describing it as the latest evolution in a trend of abusing ScreenConnect and other remote monitoring and management software. This time, the main giveaway is knowing what the vendors actually sell: None offers the Windows app being advertised. According to Allure, the campaign impersonates three unnamed US-based HR and payroll platforms by offering fake desktop clients for those providers’ software. In all three cases, those companies don’t offer a desktop client, meaning all it takes is an unaware HR or payroll clerk tricked by promises of superior performance to potentially expose some incredibly sensitive company data. Allure said that it’s not sure how potential victims are being targeted by the campaign either, but those who have been targeted may not pick up on anything being wrong. Clicking through to the website offering the fake app brings up a legitimate-looking site built using AI app builder Lovable and hosted on Vercel. The site is hidden behind the cloud host’s bot challenge page, meaning scrapers haven’t been able to index it and expose the scam. Further obscuring the malicious nature of the campaign, the downloads are hosted on a GitHub Releases page, meaning they point to a trusted domain. Once downloaded and executed, the installer presents the victim with an actual Microsoft installer to make it appear like a legitimate piece of software. It actually installs the Microsoft .NET Desktop Runtime 8.0.26, so it goes through the entire process and shows that an installation completes, but nothing ever pops up, leaving the victim unclear as to where their desktop app went. That’s not all the installer is doing, of course: It’s also running a quiet, no-interface installer to drop the ScreenConnect client on the victim’s machine. “The [ScreenConnect] access mode is set to unattended,” Allure notes. “The victim-facing indicators are turned off: no ‘your machine is being controlled’ banner, no system-tray icon, no connection balloon.” The silent install is also configured to launch on boot, and stay connected across various user sessions, giving the attacker “a quiet, persistent, interactive foothold,” says Allure. “Nothing in this chain is malware in the usual sense,” the infosec outfit said. “The page was generated by a legitimate AI builder and served by a legitimate host. The download came from a legitimate code platform. The one window the victim saw belonged to Microsoft. The thing that was installed is a legitimate RMM product, doing what it was designed to do, for someone who was never supposed to have it.” In other words, security teams have some work to do before they even check the indicators of compromise that Allure included in its report: Check with HR and payroll vendors to see if they offer a desktop app, and if not alert all members of those teams to this campaign. For those hoping they haven’t fallen victim, the actual number of victims remains unknown. Allure said the GitHub download counts across the three fake downloads totaled 291 as of its report. Some of those came from Allure’s researchers, and possibly other researchers and sandboxes too, so the download count can’t be used to determine how many victims there are. ®

❌