Two Fake Recruiters Tried to Hire a Threat-Intel Shop for a 'VP of Security' Job Before Breakfast. Same Script, Two Gmail Accounts, and a Hiring System That Does Not Exist.
At 04:16 UTC this morning, a recruiter named Juliana emailed Patrick about a VP of AI and Security Architecture role at a very large, very famous endpoint security company. At 06:59 UTC, a recruiter named Kelly emailed about an AI Security Manager role at a regional accounting firm, signing herself as a talent acquisition director at a different, even larger accounting firm. Both wrote from Gmail. Both sent the same document. Neither of them exists.
Somebody looked at a threat-intelligence shop whose entire job is reading other people's lures, and decided to lure it. We are honestly a little touched.
What arrived
Two messages, two personas, one template. Both were titled "Full Job Brief." Both opened with "Thank you for your interest," which is a bold way to start a conversation nobody had asked for. Both laid out a company, a title, a reporting line, a responsibilities list and an ideal-candidate list, and both closed with the same three numbered screening questions, word for word: your notice period, the compensation you would consider, and your preference on travel, hybrid or remote.
Kelly's subject line read "Subject Full Job Brief," with the word "Subject" pasted in. That is what a copy-paste from a script file looks like when the operator is working fast across a list.
The brands named in these emails were impersonated. None of the three companies sent anything, and none of them is involved. If you want to know whether a role is real, go to that company's own careers site and search for it there. Do not use a link from the email.
A short reply to the first message drew a resume request within minutes, plus a promise to "coordinate a meeting with the Hiring Manager." The resume, the email said, would be reviewed "for alignment with the role and our RHS-INT Systems (Recruitment & Hiring Systems – Integrated) standards." We searched for RHS-INT Systems in our corpus and on the open web. It is not a thing. It is a phrase built to sound like a thing.
The tells, in the order they showed up
A big brand on a personal mailbox. The senders were [email protected] and [email protected]. Recruiters at large companies write from the company's domain, or from a named staffing agency's domain. A first name, a last name and three random digits at Gmail is a throwaway.
Authentication that proves nothing useful. Both messages passed SPF, DKIM and DMARC, for gmail.com. That proves Google sent them. It says nothing about whether the person behind the account works where they claim. Do not let a green checkmark in your mail client do your verification for you.
One script, two personas. Identical structure and identical screening questions from two different "recruiters" at two different "companies," two hours and forty-three minutes apart. Real recruiters at real firms do not share a template with their competitors.
A story that does not hold together. Kelly signed as a director at one accounting firm while pitching a role at another. Juliana's brief for a security architecture executive asked for "100%+ quota attainment," a sales-role line that wandered in from another template.
Gratitude for interest you never expressed. "Thank you for your interest" is how they skip the part where you would ask who they are.
Pay questions before pay answers. They want your number first. That is useful to a negotiator, and also useful to someone building a profile of you.
Speed. A resume request within minutes of a reply. Real hiring pipelines are slow. Scripts are fast.
An invented process. "RHS-INT Systems" exists to make the next ask feel procedural.
Where this funnel usually ends
We stopped after step three: no resume went out and no call was booked. So we can tell you what we saw, and we cannot tell you what the operator intended. Attribution here is unknown, and we are not going to guess.
What we can tell you is where funnels shaped exactly like this one end up, because we have written about the destination. The "hiring manager" call is where you get asked to install a meeting app you have never heard of, open an "assessment" repository and run it, or click an onboarding link. That is the move North Korean operators have used against developers at scale, which we covered two days ago in North Korea Robbed an Exchange and Thirty Thousand Developers in the Same Week. The cheaper versions of the same funnel end in identity theft built on your resume, or in a request to pay for "equipment" or "training" that never arrives.
Whoever runs this one, the shape is the warning. You do not need to know who is holding the hook to stay off it.
If one of these lands in your inbox
Look up the role on the company's own careers site. If it is not there, it is not real.
Ask for the recruiter's corporate email address, and say you will send your resume there. A real recruiter can do that in one line. A fake one goes quiet.
Never install software, run code, or open an "assessment" repository for a first conversation. Real interviews happen on the tools the company already uses, and nobody needs your machine to run their code before they have met you.
Never pay for anything to get a job: not equipment, not training, not a background check.
Report the email as phishing in your mail client, report the profile if they also reached you on LinkedIn, and report the attempt to the FTC at reportfraud.ftc.gov. Each report takes a persona off the board before it reaches someone who is out of work and more likely to say yes.
What we did with it
The two sender addresses are published above. This is a first-party observation: it arrived in our inbox, today, and nobody else had published this template when we looked.
One honest gap turned up while we were filing it. Our verified ingest path accepts IP addresses, domains, URLs, hashes, packages and chain addresses, and it refused both email addresses as an unsupported type. So these two indicators are in this post and not yet in our feed. We found the hole by trying to use it, which is the only way holes ever get found. Adding email as an accepted type was a one-line change; it is committed and ships with our next deploy, and the two addresses go into the feed right after.
The part where we laugh
Of all the inboxes on the internet, someone spent a script on the one belonging to the people who write the blog posts about scripts. We would like to thank Juliana and Kelly for the material, for the free sample of their template, and for "RHS-INT Systems," which is going on a mug.
To everyone else: the job market is rough, and these operators know it. That is why they are aiming at security people and executives with titles that sound like a promotion. The fix is boring and it works. Verify the role at the source, keep your machine out of the first conversation, and never pay to be hired. We hold that advice at about 95 percent confidence. The other 5 percent is the new template they will write after reading this.
Was this useful? Rate this post. The widget is at the bottom of the page, and we read every response.
Every indicator in this post is in the feed. Free.
1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.
Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=two-fake-recruiters-tried-to-hire-a-threat-intel-shop-for-a-vp-of-security-job-before-breakfast-s




Comments