
The episode discusses a job scam that targets job seekers by asking them to paste a terminal command, which can lead to malware infection.
I ran into a strange hack this week. It looks simple at first, but it is not. It targets job seekers. I think I recall submitting a resume for a job at a company called Runeapes, which, at least on the surface, looks like a real website. You get a message saying you missed an appointment. It points you to a booking page. The name looks normal, the flow looks normal. You click through, pick a time, go through the usual steps. Nothing stands out. Then it asks you to get ready for the meeting. There is a download for Windows, which is expected. Then there is a “download” for macOS. That is where things change. Instead of a file, you get a terminal command. A curl command. It tells you to paste it into your terminal. If you’re not technical, this step can inject so much malware into your system that you’ll probably be hacked for life. That should stop you right there. The command points to a domain that looks real at a glance but is not. The domain was created recently. Same with the app domain tied to the booking flow. Both showed up within the past month or so. I started poking around. The site has all the usual pages: Pricing, About, Blog, Careers, Contact. Every single one is…
Explore listener stats, chart rankings, contacts and more on the Keep Going podcast page.