CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps
A large-scale phishing campaign, dubbed RecruitTrap, is targeting over 3,000 recruitment-related URLs to steal Google and Facebook credentials, and in some cases, relay MFA prompts in real-time. The campaign uses Browser-in-the-Browser (BitB) techniques to mimic legitimate recruitment portals and scheduling pages, leveraging a shared infrastructure and sophisticated rebranding to target valuable enterprise identities, primarily in recruitment, technology, luxury goods, and travel sectors. Users should verify unsolicited recruitment invitations through official channels and organizations should implement phishing-resistant authentication and monitor for suspicious activity.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
