Is that job posting real? Check it before you apply.
Some job listings are ghosts. Some are traps. Choose a one-time check, or let an agent remember what job boards looked like and correlate the warning signs over time.
What do you want to do?
The autonomous path requires a local AI agent and a logged-in browser you control. It never treats “old” as proof of fraud.
Autonomous correlation & reporting
This is the part a one-time AI prompt cannot do. The watcher remembers what it saw, compares new observations with its history, verifies the strongest leads, and builds a report packet instead of making a vibe-based accusation.
What it can report
Requests for money, checks, identity documents, credentials, or code execution; apply links that do not belong to the employer or a recognised ATS; brand impersonation; a posting absent from the employer's own reachable careers page; and the same role left on multiple boards for 60+ days.
A local agent, a browser session you control, permitted sources or job alerts, and the reporting policy you are comfortable with.
Longitudinal correlation, evidence packets, queue state, deterministic safety decisions, pacing, duplicate protection, and an audit trail of filings.
Download the autonomous reporter bundle or use the single-file agent skill. If BrowserOS neo is missing, the skill bootstraps it from the official release source and validates the local browser connection. It runs locally through your own agent and browser session; this website does not receive the postings you investigate.
One-time check: use the prompt
For a single posting, recruiter message, or company, copy the prompt into ChatGPT, Claude, Gemini, Copilot, Grok, or another AI that can browse. Then paste the job material underneath it.
No install is required for this path. The job text is not sent to this website, but anything pasted into a third-party AI tool is subject to that tool's privacy settings. Never paste passwords, ID documents, MFA codes, or private financial information.
Show the copy/paste prompt
You are my personal job-posting investigator. I am a job seeker, not a security professional. I will paste a job posting, a recruiter message, or a company name and job title below. Your job is to tell me whether this is safe to engage with, and exactly what I must not do. HOW TO RESEARCH 1. Use web search. Prefer primary sources: the employer's own website and careers page, the actual posting, company records, news reporting. Do not treat other job boards, AI summaries, or your own memory as confirmation. 2. Check the employer's OWN careers page. Search for site:employer-domain plus words from the job title. Tell me whether the role is actually listed there. 3. Posting dates. Find the earliest date you can see on each platform. If platforms disagree, say so. If you cannot see any date, say that. 4. Where does it apply to? The employer's own domain, or a recognised applicant tracking system (Greenhouse, Lever, Workday, iCIMS, Ashby, SmartRecruiters, Workable, BambooHR, Jobvite)? If the apply link goes anywhere else, treat it as a serious warning and tell me the exact domain. 5. The recruiter. Is this person findable at that employer on the employer's own domain, a corporate directory, or a press release? A LinkedIn profile alone is not proof. 6. Published warnings. Search "COMPANY fake recruiter", "COMPANY impersonation", and search the recruiter's email address and phone number in exact quotes. 7. Red flags to look for and report if present: any request for money, gift cards, crypto or an equipment purchase; a cheque to deposit; requests for SSN, bank details, driver's licence or passport photos, tax forms, passwords or MFA codes; interviews only on Telegram, WhatsApp or Signal; a "coding assignment" or tool I am told to download and run; an offer with no real interview; refusal of a video call; pay wildly above market for the stated requirements. RULES YOU MUST FOLLOW - Never state that a posting or company is a scam, fraudulent or illegal as settled fact. Use "risk indicators". Separate VERIFIED, INFERRED and COULD NOT CHECK. - Never invent a company, person, date, link or search result. If a search returns nothing, say it returned nothing. - Age matters: any listing open or re-listed for more than 60–90 days is a fake requisition / ghost job. Flag any posting older than 60 days or with high applicant churn as a ghost listing. - If you cannot browse the web in this conversation, say so immediately, then give me the exact searches and pages to check myself instead of guessing. - Never draft an accusation against a named company unless I give you direct evidence. GIVE ME EXACTLY THIS, IN THIS ORDER VERDICT: one of [looks legitimate / ghost job (open >60-90 days) / cannot verify / high risk / likely a scam] RISK: low, moderate, high or very high CONFIDENCE: low, medium or high, plus one line on why STRONGEST EVIDENCE: up to 5 findings, strongest first, each with the source you used COULD NOT VERIFY: what you could not check, and how I check it myself in one step EXPLANATION: the context, including whether this is an abandoned or ghost requisition DO NOT: the specific things I must not do for THIS posting NEXT STEP: the single most useful thing for me to do right now REPORT IT?: yes or no. If yes, name the exact destination and give me a short factual message I can paste, with no accusations beyond the evidence. Paste your job post or recruiter message under this line.
Stop signs: do not proceed
- They send you a cheque to buy your own equipment. This is a classic and it is always fraud.
- They ask you to pay for training, software, a background check, or "onboarding" in gift cards or crypto.
- They want your Social Security number, ID or passport photos, bank details, tax forms, passwords or MFA codes before a signed offer.
- They want you to install something, run a repo, or complete a "coding assignment" on your own machine, especially with a shared credential or a browser extension.
- The interview is text-only in Telegram, WhatsApp or Signal, and they refuse a video call.
- Pay is far above market for the stated requirements, and the offer arrives fast with no real interview.
- The recruiter's email is a free-mail address, or the domain is a near-miss of the real company name.
- The job description was obviously written for a different role, or the "company" has no website beyond a one-page site registered last month.
- They pressure you on time. Urgency is the attack, not a personality trait.
The pattern behind the attacks
The documented recruitment-malware playbook is remarkably consistent. Once you know the shape, it is hard to miss.
- Approach. A recruiter contacts you on LinkedIn, WhatsApp, Discord or Telegram, usually for a role that matches your skills exactly. Often for a company you cannot quite place: an AI startup, a crypto project, a Web3 venture.
- Flattery and speed. The process moves fast. You are exactly what they are looking for.
- The task. A technical interview, then a "coding assignment", a repository to review, or a request to "fix an error" in their video-conferencing tool. You are asked to download a file or install a package.
- Compromise. The archive, repo or npm package carries malware. Documented families include BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle. What follows is theft of credentials, crypto wallets, browser data and source code.
Facilitators and "laptop farms" are used to make the operation look real, and some campaigns have recruited people to run the malware from inside the target company. In the reverse direction, DPRK IT workers use stolen or synthetic identities to obtain genuine remote jobs, which means a suspicious posting can also be a real posting being abused by a fraudulent applicant.
Field notes: what stale postings actually look like
On 5 October 2026, we audited 723 live job listings across core IT and cybersecurity roles (Cyber Security Analyst, Security Engineer, System Administrator, IT Manager, and Network Engineer across remote, hybrid, and on-site postings). We extracted the platform’s underlying listing metadata — original post dates, re-list churn, and published applicant counts — to see what job seekers are actually up against.
Real-world cases captured during the audit. These patterns highlight why applicants waste countless hours: postings left open for hundreds of days, recycled requisitions with hundreds of applicants, and suspicious phantom companies.
| Pattern | Company | Role | What the record showed |
|---|---|---|---|
| Longest running | aizoOn USA | Cyber Security Analyst (Rif. 2025-127) | First listed 410 days earlier and re-listed since; 200+ applicants published; hybrid. |
| The same role twice | At-Bay | Sr. Cyber Analyst, DFIR · Cyber Analyst, DFIR | Two separate listings for one specialism, both 336 days old, 200+ applicants each. |
| Re-listed at 294 days | Skydio | Technical Support Specialist | 294 days on the board, re-listed rather than closed, 200+ applicants. |
| Re-listed at 262 days | Axway | Senior Cloud Systems Administrator | Scottsdale, hybrid, 262 days, 200+ applicants. |
| Three roles, all re-listed | Prestige Staffing | System Security Analyst · Security Engineer · Cloud Security Engineer | 251, 161 and 140 days — each one re-listed instead of closed. |
| Eight titles in one minute | RemoteHunter | Staff Security Engineer, AI Security Engineer, Network Engineer, and five more | Eight senior titles published inside the same minute; the company’s own record lists two employees. |
| No employer named | “Stealth Startup” | Technical Support Lead | Three listings with no company identity. The platform’s company record for that name claims 37,852 employees, so the record is a placeholder. |
| Duplicate requisition pair | Interra Health | Technical Support Specialist, L2 | Two identical requisitions, 52 and 55 days old, 200+ applicants each. |
| Same role, three locations | Mercor | Ubuntu Desktop Expert — “Upto $70/hr” | One role duplicated across three locations, with the pay rate in the title. |
| Thin posting, crowded | High Sierra Talent | Information Technology Support Specialist | Ten days old with a very short description, 200+ applicants, and a company record listing one employee. |
The 60–90 Day Reality Check
If a company keeps a listing active or repeatedly re-listed for more than 60–90 days while accumulating 100+ applicants, it is a fake requisition or an abandoned ghost job. Genuine hiring teams do not leave an active, funded role open for 200–400 days while ignoring hundreds of qualified submissions.
Companies run these phantom listings to fake growth signals for investors, build evergreen resume databases without intent to hire, or placate burned-out staff by pretending “help is coming.” Worse, unmonitored stale listings frequently get hijacked by threat actors running recruiter lures and malicious coding interviews.
Bottom line: If a job posting is older than 60 days, verify it on the employer’s official careers portal first. If it isn’t an actively featured priority there, do not waste your time or surrender your personal data.
Corrections and removals: if a fact above is wrong, or a role has since been filled or closed, tell us and we will correct or remove the entry.
If you already clicked, ran it, or sent something
Stop researching and act. Speed matters more than completeness. Work these in order. Do the top three now.
- Get the machine off the network. Disconnect the cable or turn off Wi-Fi. If you are unsure how bad it is, power it off and use a different device for everything below.
- From a clean device, change your email password first, then your password manager, then code hosting, cloud storage, and banking. Email first, because email is how everything else gets reset.
- Kill the sessions. In each account, sign out all other devices and revoke active sessions and tokens. Rotate MFA where you can.
- Remove what they gave you. Delete the repository, the package, and any IDE config, task file, or browser extension the "assignment" added.
- If crypto wallets were on that machine, assume they are gone. From a clean device, generate a brand-new wallet and move funds there. Revoke token approvals on the old one.
- If you sent money, call your bank now and ask specifically about a recall or chargeback. Wire and ACH recalls work best within hours.
- If you sent ID or SSN: place a free credit freeze with all three bureaus, file at IdentityTheft.gov, and request an IRS Identity Protection PIN. Report to the SSA fraud hotline if your Social Security number was exposed.
- Report it: IC3 at ic3.gov and the FTC at ReportFraud.ftc.gov. Include file hashes, URLs and the amount lost.
- If it was a company device, tell your employer's security team immediately. Their incident response takes priority over doing this quietly yourself.
- Expect a follow-up scam. After a breach, victims are targeted by "recovery" services asking for payment. Nobody legitimate charges you to get your money back.
How to report a fake posting
Reporting is optional, and it is the part that actually helps the next person. Do it well: one strong, factual report to the right place beats fifty vague ones. Several of these only act on patterns, so a precise report is worth more than an angry one.
Report facts only. Do not accuse a company of a crime you cannot evidence, and do not organise a pile-on. That is how a useful report becomes a legal problem for you.
- The platform hosting the posting. Fastest real-world effect, because it removes the trap for everyone else. Use the platform's own report or flag control.
- The employer being impersonated. Use the contact details published on their own website, and tell them their name is being used. Brand and security teams care about this and can act quickly.
- The abuse desk for the domain. If the apply link is not the employer and not a real applicant tracking system, report it to the registrar of that domain. The registrar's abuse contact is published in its registration record.
- The hosting provider. Report malware or phishing content to the abuse desk of the company hosting it.
- Government. IC3 for cybercrime and financial loss, FTC for deceptive practices, and your state attorney general for consumer matters.
- The Better Business Bureau is worth using only if you had a real marketplace relationship with the business. A BBB complaint is not a fraud hotline and it is not the right venue for an anonymous listing you never engaged with.
A short factual report contains: what you saw, the exact URL, the date and time, what you were asked to do, what you sent or ran, and what it cost you. Nothing else is needed, and anything more weakens it.
Questions
How do I know if a job posting is fake?
Check the employer's own careers page first. If the role is not listed there, treat that as a warning. Then check where the Apply button actually goes: it should be the employer's domain or a recognised applicant tracking system. Finally, verify the recruiter through the employer's own website rather than through a contact in the message.
What is a ghost job?
A fake or abandoned posting kept live without genuine intent to hire. When a role sits open or gets recycled past 60–90 days while racking up hundreds of applicants, it is a ghost requisition. Companies run them to project phantom growth, build evergreen resume pools, or placate burned-out employees. They waste your time and expose your personal data.
Are fake job interviews really used to install malware?
Yes, and at scale. The 18 September 2026 IC3 advisory on WaterPlum, also known as Contagious Interview, documents more than 30,000 compromised systems across over 100 countries, with the malware delivered through supposed coding assignments. See the advisory linked above.
Should I run a coding assignment from an interview?
Not on a machine you care about. Malicious assignments, repositories and packages are the primary delivery method in documented campaigns. If you must inspect one, use a disposable virtual machine with no saved credentials and no access to your personal or work accounts.
What should I never send a recruiter?
Never send your SSN, government ID or passport photos, bank details, tax forms, passwords or MFA codes before a signed offer and a verified human contact. No legitimate employer sends you a cheque to buy your own equipment, and none requires payment, gift cards or crypto at any point in hiring.
Does a long-open or reposted job mean it is fake?
If a listing has been open or repeatedly re-listed for more than 60–90 days, yes — treat it as fake. Legitimate hiring teams fill active, funded requisitions. Postings sitting on boards past 60–90 days with hundreds of applicants are ghost jobs used to harvest resumes, fake business growth, or pacify overworked teams. Stale postings are also prime targets for threat actor spoofing.
Is this legal or career advice?
No. This is general information about verifying job postings and protecting yourself. It is not legal advice, and it is not a substitute for your own judgement or professional advice.
