Hacker(s) are using freelancing websites like Fiverr and Freelancerto distribute malware through job offers. These ads contain files that supposedly contain detailed information about the job that needs to be done. Instead, these malicious files contain keyloggers or RATS (remote access trojans).
For example, in the screenshot below we can see how the attacker sends the malicious file to an unsuspecting freelancer, asking for their help with a job.

According to the Malware Hunter team, this type of attack is used on many platforms such as Fiverr, Freelancer, and others. There is evidence that several users have "run" the files and become infected.
Saw an NG actor using @fiverr to spread.
And in this case, the poor girl opened the doc...
People, if you are opening files from random people, at least have an AV installed. And of course, don't enable macros… pic.twitter.com/nfC3ahmMUj— MalwareHunterTeam (@malwrhunterteam) September 21, 2018
The reason why users have difficulty understanding that the file is infected is because most accounts that request freelancers provide job details via doc or pdf files.
Some of the users even tried to open the files in question from their mobile phones, and failed. So they sent a message to the malicious hacker's account, asking for help. The hacker, in an effort to infect as many computers as possible, replied that the file must be opened from a computer.
Finally, we can see that Hackers not only use innovative tricks to spread their malware, but also dedicate the necessary time to helping their victims get infected.
As always, it is important to have an up-to-date anti-virus installed on your computer, and to check all files before executing them, in case you do not trust their source.
