www.ctm360.com
RecruitTrap Scams Exploit Browser-in-the-Browser Technique for Credential Theft
Article Content
A global phishing campaign named RecruitTrap has emerged, targeting corporate credentials through fake interview invitations and counterfeit scheduling portals. The attackers utilize Browser-in-the-Browser (BitB) techniques to create realistic login prompts that mislead victims, particularly on mobile devices where visual cues are limited. Over two months, more than 3,000 phishing URLs impersonating various organizations were identified, with a focus on marketing professionals. The campaign employs strict filters to ensure only corporate email accounts are used, facilitating credential theft and potential account takeover. Zimperium's telemetry indicates a long-standing threat pattern, with attackers relying on a persistent infrastructure to host these scams. Major brands like Amazon, Apple, and Deloitte have been noted as targets. The phishing kits actively screen inputs, rejecting personal email domains to focus on high-value enterprise access. This ongoing threat poses significant risks to organizations, as attackers can gain access to OAuth tokens and internal communications once credentials are compromised.
Key Points: • RecruitTrap uses BitB techniques to deceive victims into entering corporate credentials. • Over 3,000 phishing URLs have been identified, primarily targeting marketing professionals. • Attackers filter for corporate email accounts, enhancing the likelihood of successful credential theft.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.