The Fake Resume Scam That’s Actually Malware — And How It Fools Careful Hiring Teams
The resume looked exactly like what you’d want to see. The candidate’s experience lined up with the open role, the writing was sharp and professional, and their LinkedIn profile matched the resume line for line. Over a few days, a handful of easy, friendly messages went back and forth about the position — nothing that raised an eyebrow. Then came a follow-up email: a link to download the full resume from a file-sharing site the recruiter hadn’t used before. By that point, the conversation already felt like it was with someone real. One click on that link, and malware was quietly installing in the background.
Security researchers have a name for what just happened: a fake resume malware scam built specifically to slip past careful, well-meaning hiring teams.
A Task Nobody Thinks Twice About
Reviewing resumes is one of the most routine tasks in any office — which is exactly why it’s become a favorite target for attackers. HR staff and hiring managers open unfamiliar attachments from strangers all day, every day, because that’s the job. Nobody expects a resume to be dangerous, and that’s the whole point.
What makes this scam effective isn’t a clever piece of technology. It’s patience. The fake applicant profiles researchers have tracked are genuinely convincing: real-sounding names, believable work histories, professional writing, sometimes even an active LinkedIn presence to match. There’s rarely an awkward typo or a strange request early on to give the game away. The initial contact usually happens on a legitimate platform too — a job site like Indeed or a message through LinkedIn — which is part of why it works. A recruiter has no reason to be suspicious of a conversation that started somewhere they already trust and already use every day.
The danger doesn’t show up until the conversation moves off that platform. A follow-up email arrives with a link instead of an attachment, and often the sender asks the recipient to manually type that link into their browser rather than click it. That’s a deliberate move, designed to slip past email security filters built to scan for clickable links and file attachments. By the time that email lands, the recruiter has already built a bit of rapport with “the candidate” through a few genuine-feeling messages — which makes clicking through feel like the natural next step instead of a risk worth pausing over.
How the Resume Malware Scam Actually Works
Here’s what actually happens once that link is opened. It leads to a professional-looking resume download page, sometimes gated behind a quick CAPTCHA. That step is designed to look like routine verification, but its real purpose is filtering out the automated security scanners that would otherwise catch the download before a human ever sees it. What downloads next isn’t a resume at all. It’s a disguised file that runs hidden commands the moment it’s opened, quietly installing malware built to steal passwords and business data in the background — no obvious pop-up, no error message, nothing that would tip off the person who just clicked download.
This fake resume malware scam isn’t a brand-new playbook, either. Security researchers at Arctic Wolf Labs have traced versions of this scheme back to around 2018, when the group behind it was originally focused on retail payment systems, targeting industries like retail, entertainment, and pharmacy to steal customer card data. In recent years, the tactics shifted almost entirely toward HR departments and recruiters — a far broader target, since virtually every business hires eventually. It hasn’t slowed down since: Aryaka’s threat research team has continued tracking active, evolving versions of this same approach well into 2026, which tells us this pattern isn’t a passing trend small businesses can safely wait out.
That evolution matters for one reason: the mechanics keep getting refined precisely because they keep working. The good news is the pattern itself is easy to recognize once you know what to look for — rapport built on a legitimate platform first, then a pivot to an external email with a link instead of an attachment, then a request to manually retype that link rather than click it, then a file format that has no business being called a resume in the first place. Four steps, every time, whether the target is a two-person office or a company with a full HR department.
What This Means for Your Hiring Process
Only accept resumes in standard formats. A PDF, Word document, or plain text file is all any applicant needs. If a “resume” arrives as a .zip, .iso, or .exe file, that’s your red flag — no legitimate applicant needs an unusual file format to share a one- or two-page document.
Treat a manual-retype request as a warning sign. If someone asks you to copy and paste a link into your browser instead of simply attaching a file, that’s a known trick used to dodge email security filters — not a normal part of applying for a job.
A CAPTCHA on a resume download is a stop sign, not routine verification. Legitimate resume downloads don’t require you to prove you’re human first. Treat that step as a reason to pause, not a reason to proceed.
Being contacted through a real platform isn’t a guarantee of safety on its own. The real protection is staying inside that platform’s own messaging and application system. The moment a conversation moves to an outside email with a link to paste into your browser, you’ve left that safety net behind — no matter how legitimate the first contact felt.
When anything feels the slightest bit off, call us before opening it. We’re always happy to take a look at a file, a pop-up, or a download before anyone on your team clicks through. It takes us minutes, and it can save you a very bad week.
Questions to Ask Your IT Team
- Does our email security actually flag resumes that arrive as a link instead of a direct attachment?
- If a fake resume made it past our filters and someone opened it, would we know within minutes — or find out weeks later?
- Do our HR and hiring staff know what a legitimate resume download should, and shouldn’t, look like?
- Who on our team can HR call the moment something about an application feels off — before anyone clicks anything?
The Takeaway
You can’t screen every applicant down to a certainty, and you shouldn’t have to run a background check on every friendly LinkedIn message before responding to it. What you can control is the file types your team accepts, how closely you watch the moment a conversation moves off-platform, and whether your hiring team knows exactly who to call the second something feels wrong. This scam works because it hides inside a task nobody thinks twice about. The fix is making sure your team thinks twice — just for a second — right before they click.
As always, remember that your Paradigm team is just a call, email, or text away for any questions or concerns that may arise.
If you’d like us to take a look at your current email security settings and how they handle resume attachments and links, we’re here to help. No pressure, no sales pitch — just an honest conversation about where you stand.
— Your Paradigm Team
P.S. If phishing scams like this one are on your radar, our blog on spotting 2026’s phishing emails breaks down what else has changed this year. Worth a read. [Link — Blog 5: Phishing Emails 2026]