Back News.Lavx.Hu Fake Google security-team ad bans script reading, then prints the script
A Telegram recruitment post for a suspected Google voice-phishing operation told callers to avoid scripts while publishing the exact words they were expected to use. Trellix highlighted the contradiction in its latest Dark Web Roast report.
A Telegram recruiter seeking callers for a suspected Google security-team scam banned script reading, then published the script those callers would use.
Trellix’s Advanced Research Center documented the contradiction in its latest Dark Web Roast , a series that uses memes and mockery to expose criminal activity on underground forums.
The August post appeared in a U.K. fraud channel under the name Derian, according to Trellix. The recruiter sought male and female callers in the United States and Canada with “white sounding” voices. The listing placed “NO SCRIPT READING” in bold text before giving applicants a prepared opening line.
The proposed call began with a fake introduction from the “Google Account Security Team” and asked to speak with a named account holder. The recruiter also described the call as taking place on a recorded line, a detail intended to make the fraud sound like a compliance check.
Trellix analysts mocked the post’s quality-control process while warning readers that the operation could still harm victims. The company’s report treats the scam as a source of dark humor, but it also points to the growth of organized social engineering work on criminal forums.
John Fokker, Trellix’s vice president of threat intelligence strategy, said the Dark Web Roast grew from a desire to strip criminal groups of the mystique that often surrounds them. He said threat actors remain ordinary criminals who use computers to steal data and money.
The approach targets recruitment, branding and operational claims that criminals use to attract partners. A scammer who advertises voice callers, payment terms or technical services creates a record that researchers can study. Those posts also show how criminal groups divide labor among recruiters, callers and operators who handle stolen accounts.
The FBI’s Internet Crime Complaint Center recorded $20.87 billion in reported internet-crime losses during 2025. That figure covers many forms of fraud, including scams that rely on phone calls and social engineering.
English-language social engineering has become a sought-after skill on criminal forums. A ReliaQuest analysis found that job ads mentioning the skill more than doubled between 2024 and 2025.
Google has also described voice phishing, or vishing, as a major route into corporate systems. The tactic ranked second among the most common methods criminals used to gain initial access and ranked first in attacks against cloud environments, according to the source material cited by Trellix.
A phone scam needs little specialized equipment. A caller needs a convincing pretext, a target list and enough account detail to keep the victim engaged. The operator may then push the target toward a password reset, a remote-access tool, a payment or a transfer of sensitive data.
Organizations can reduce the risk by training staff to distrust unsolicited security calls, verifying callers through known channels and requiring a second approval for account changes. Cloud administrators should also monitor unusual sign-in patterns and review help-desk requests that involve password resets or changes to multifactor authentication.
The Telegram post exposes a careless recruiter. The larger pattern shows a mature criminal labor market that continues to package phone fraud as ordinary contract work.
Please log in or register to join the discussion
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
