The #ROCK phishing group has targeted some weeks ago the recruitment website Careerbuilder.com. I was at that time very sceptical and surprised about that, as no financial data were trying to be stolen through these phishing campaigns.

We today have a more precise idea of what these pirates may have been trying to do. We recently saw a job offer on careerbuilder.com that originates from the #Rock group and promotes their mule recruiting websites (in this case AEGIS Capital Group LLC. This website is offline, but you can still see copies of it here or here for example):


As users are nowadays more aware of email scams and particularly representative scams, the phishers have found new ways to propagate their fraudulent job offers. Who would not trust such famous websites as Careerbuilder or Monster indeed ?

Update: A few days ago the gang set up a new template for these mules recruitement websites called "Sydney Car Centre":

  • http://sycarcentre.io
  • http://sydneycentre.io
  • http://scarcentre.hk
  • http://cccentre.hk
  • http://sydneycc.hk
  • …