Skip to main content

Choose your country

Article

One Scam, Many Disguises: The Job Scam Built to Be Reused

Jeremy Ong

10 min read

We've seen fake recruiters on LinkedIn impersonate legitimate companies, advertise convincing vacancies, and recreate parts of the hiring process to win job seekers' trust. But not every job scam is built around a high-stakes career opportunity. Sometimes, the proposition is much simpler: easy work, easy money, and seemingly little to lose.

That's how a job scam recently tracked by F‑Secure begins.

The scam stays the same, the brand changes

A social media ad offers extra income for completing simple tasks, before moving victims through an intermediary website, WhatsApp, and Telegram, to what appears to be an Oppo Malaysia job portal. There, they're asked to deposit RM28 to activate their account, and initially, they can withdraw more than they put in. Once that trust is established, the requests for larger deposits begin. This time, it's money that they won't see again.

Oppo is only the latest disguise. That same operation has impersonated 7-Eleven, New Balance, and Watsons, with lookalike domains also registered for Samsung and Trip.com. The brands change, but the scam doesn't. We examine the playbook behind it and what makes it so easy to reuse.

It starts with the promise of easy money

The scam begins the way many "task-based" job scams do: an ad on social media offering easy money for completing simple online tasks. In most cases, these ads link users directly to WhatsApp to initiate the conversation.

In this instance, however, users are first directed to an intermediary site (kwgtop[.]org) which acts as a funnel rather than the destination. From there, the visitor is handed off to a WhatsApp contact, either a real person or an automated account, who takes over the conversation.

A fake job ad promising RM50–RM200 per day (left) leads to a landing page impersonating Watsons Malaysia (right).

Moving the conversation out of sight

The conversation doesn’t stay on WhatsApp for long. After the initial contact, the handler moves the chat over to Telegram, where the rest of the “recruitment” plays out. This isn’t just a convenience switch: Telegram groups can be configured to block screenshots and screen recordings, making it harder for victims or investigators to capture and preserve evidence of what’s said and shared inside the group.

Once on Telegram, and after a bit of back-and-forth chat to build rapport and answer questions, the handler sends a link to the “job” site (oppomypartner[.]com). The site is styled to look like it belongs to Oppo, the phone manufacturer, with numerous AI‑generated images, and this is where the scam really gets going.

The oppomypartner[.]com landing page, including a fabricated “already used by 39,998 people” counter for false legitimacy.
An AI-generated 'Download Telegram, claim RM8' graphic.

Signing up isn’t open to anyone. Registration requires an invite code, which, conveniently, the handler provides. This small step matters: it makes the scam feel more exclusive and keeps control of onboarding entirely in the scammer’s hands, rather than letting people stumble onto the site on their own.

The illusion of money already earned

Before any money changes hands, the account dashboard already shows a balance. New sign-ups are credited with RM200 immediately, and shortly after, the operator announces a special “promotion day” and adds another RM300, bringing the on‑screen total to RM500, without the victim ever paying in.

None of this is real money. It’s a number in a database designed to look like earnings already sitting there, ready to withdraw. That’s the psychological setup for the next step: a small deposit will feel trivial when it’s framed as the key to unlocking hundreds of ringgits that appear to be sitting right there waiting.

A small payout makes the opportunity feel real

To “activate” the account and unlock the balance, new “employees” are told they need to deposit RM28. In return, they’re promised a 50% “bonus commission” of RM14, meaning their very first cash-out comes to RM42.

This is the oldest trick in the task scam playbook: a small, real payout early on to build trust before larger “investments” are requested later. It’s designed to feel like proof that the scheme works. When in reality, it’s simply priming the victim to deposit more money down the line.

The handler’s deposit breakdown (RM28 → RM14 → RM8 → RM42), false PIDM “certification” claim, and Telegram posts showing supposed successful payouts. The figures don’t add up: RM28 + RM14 = RM42, leaving the RM8 unexplained.

Money in motion: rotating mule accounts

The RM28 deposits don’t go to a single, static account. At the time of writing, F‑Secure has observed the operation cycling through multiple mule accounts held with Ryt Bank and GX Bank, with the operators switching to new account numbers roughly twice a day. This rapid rotation makes the money trail harder to follow and helps the scam survive even after individual accounts are flagged or frozen.

Adding another layer of theater, there’s a Telegram group tied to the operation where members share screenshots of themselves transferring RM28 and “receiving” RM42 back. It’s unclear whether these are genuine participants or staged accounts meant to manufacture social proof. Either way, the effect is the same: newcomers see “real people” getting paid and feel reassured enough to hand over their own money.

After the warning goes public, the scam changes brand

Oppo Malaysia has since addressed this directly on its Instagram account, warning followers about an ongoing scam that uses its name and links to oppomypartner[.]com. That statement is consistent with F-Secure’s own observations.

Oppo Malaysia’s Instagram post warning about the scam, naming oppomypartner[.]com directly and directing victims to Malaysia’s National Scam Response Centre (997).

What’s notable is what happened next. Continued tracking of this campaign has shown the same group impersonating other well-known brands, including 7-Eleven, New Balance and Watsons. Shortly after Oppo’s public statement, the operators registered new domains impersonating Samsung and Trip.com.

Calling out one fake brand didn't shut down the operation. The operators simply moved on to new ones, using the same playbook: a social media ad, an intermediary site, a WhatsApp-to-Telegram handoff, an invite-only “job” portal, a small deposit, and promises of larger returns.

The same playbook could extend beyond Malaysia

There's little in this playbook that ties it specifically to Malaysia. The funnel site, chat-app handoff, invite-gated portal, and small-deposit hook could all be reused elsewhere by changing the brands, currency, and banks involved.

At the time of writing, F‑Secure has not identified any cases outside Malaysia. But given how quickly the group switches domains and impersonated brands, the same playbook could easily be adapted for other markets.

The same fake storefront template redeployed for Samsung. A Galaxy S24 Ultra landing page with its own fabricated “used by 44,228 people” counter.

How to spot job scams like this

A few warning signs appear consistently in this scam and others like it:

  • Job offers promising easy money for vague tasks. Be cautious when supposed recruiters offer simple work for unusually easy returns, particularly when the conversation quickly moves from social media to WhatsApp or Telegram, and the entire “hiring” process takes place over chat.

  • Requests to pay before you can earn. A job should pay you, not require you to deposit money to activate an account, unlock tasks, or access supposed earnings. Treat any request to pay money for these reasons as a major warning sign.

  • A balance you didn’t earn. If a dashboard shows money already credited to your account through a “sign-up bonus” or promotion before you’ve done any real work, don’t assume it’s yours. A number on a screen is not proof that the money exists or can be withdrawn.

  • Invite codes and exclusivity. A requirement to use a code supplied by the person recruiting you can keep you dependent on that person and make the opportunity appear more exclusive or legitimate than it is.

  • “Proof” from other users. Screenshots and messages showing supposed deposits or successful payouts can be fabricated or coordinated. Don’t treat activity in a group chat as evidence that an opportunity is legitimate.

  • Warnings from the impersonated company. Check the company’s official website and social media accounts independently. If the company is warning about a scam using its name, don’t trust the site or contact claiming to represent it.

What to do if you’ve engaged with a job scam

  • Stop sending money. Don’t make another deposit because you’re told it will release the money you’ve already paid.

  • Save the evidence. Keep screenshots of conversations, websites, invite codes, payment instructions, and bank account details.

  • Contact your bank and report the scam. If you’ve transferred money, contact your bank as soon as possible. You should also report the incident to the police or the appropriate fraud or cyber crime reporting service in your country.

  • Warn others. Let friends, family, or colleagues know about the scam, particularly if they may have seen the same ad or been approached with a similar opportunity.

Anatomy of the scam

The scam unfolds across the F‑Secure Scam Kill Chain as follows.

Reconnaissance and Target Acquisition

  • 1.1 Establish target pool based on suitability to scam: Ads placed on social media targeting people likely to respond to promises of easy income for completing simple online tasks.

Resource Development

  • 2.1.4 Domain services: Registration of kwgtop[.]org as a redirect/funnel site and oppomypartner[.]com as the Oppo-branded bait site, followed by new lookalike domains for Samsung and Trip.com after the Oppo site was publicly exposed.

  • 2.4.2 Create or acquire service identities and accounts: Impersonation of the Oppo, 7-Eleven, New Balance, Samsung, and Trip.com brands.

  • 2.4.3 Create or acquire financial service accounts: Mule bank accounts identified at Ryt Bank and GX Bank, rotated roughly twice a day at the time of writing.

  • 2.5.2 Create bait website: oppomypartner[.]com, built to pass as a legitimate Oppo partner portal.

  • 2.5.3 Create bait advertisement: The initial social media ad offering paid tasks.

  • 2.6.2 Improve accuracy of brand impersonation: Visual styling of oppomypartner[.]com to resemble Oppo’s branding.

  • 2.6.5 Write social engineering scripts: Scripted handler talking points, including the captioned “RM500 (REAL MONEY)” messages shared alongside “successful activation” screenshots.

Victim Contact and Engagement

  • 3.4 Contact and engage victim via online service controlled by 3rd party: Initial contact via a WhatsApp handler after clicking the ad, framed as a job opportunity.

  • 3.5 Contact and engage victim via online services controlled by scammer: The handler shares the oppomypartner[.]com link directly once rapport is established.

Persistence of Scam

  • 4.1.5 Community building, peer pressure: A Telegram group sharing screenshots of “successful” activations and payouts to manufacture social proof.

  • 4.1.6 Gradual commitment, positive reinforcement: A fake RM200 sign-up credit and RM300 “promotion day” top-up shown in‑dashboard before any real deposit is requested.

  • 4.1.7 Reciprocity, create obligation: RM28 deposited, RM42 returned (RM28 + RM14 “bonus”), creating a sense of obligation and proof that the scheme “pays back,” and priming victims for larger asks later.

  • 4.3 Change platform used to communicate with victim: Conversation moved from WhatsApp to Telegram; Telegram groups can also be configured to block screenshots and screen recording, making it harder to preserve evidence.

Access and Exfiltrate Information

  • 5.1 Victim divulges information: Victims transfer money from their own bank account to “activate” the account, handing over real financial and identity details in the process.

Monetization

  • 7.1 Directly transfer funds from victim to scammer: RM28 bank transfers into rotating mule accounts, observed at Ryt Bank and GX Bank at the time of writing.

Indicators of Compromise (IOCs)

  • kwgtop[.]org

  • oppomypartner[.]com

  • samsungmypartner[.]com

  • malaytrippartner[.]com

  • 7-11-my-partner[.]com

  • watsonspartner[.]org

  • watsonspartner[.]info

  • watsonspartner[.]cc

  • watsonsidpartner[.]com

  • watsonspartner[.]net

  • watsonspartner[.]vip

  • tiktokplazapartner[.]com

  • watsonspartner[.]com

  • qconpartner[.]com

  • newbalancepartner[.]shop

  • onqcpartner[.]com

Expert behind the insights

Jeremy Ong

Junior Researcher, F‑Secure

Jeremy Ong is a junior cyber security researcher with interests in threat intelligence and emerging cyber threats. His work involves investigating malicious activity and exploring techniques, tools, and infrastructure used by threat actors. He has also contributed to cyber security research and publications.