Threat Intelligence
CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps
Cyber RTAugust 16, 20263 min read

Cybersecurity researchers have identified a global phishing campaign, RecruitTrap, targeting marketing professionals through fake recruitment processes. The campaign uses Browser-in-the-Browser (BitB) techniques to steal Google and Facebook credentials, even bypassing multi-factor authentication. CTM360 discovered over 3,000 phishing URLs, primarily mimicking Calendly pages. The attack exploits trust in job opportunities, focusing on high-value enterprise accounts. Users should verify interview invitations independently and use phishing-resistant authentication methods.
Cybersecurity researchers have identified a sophisticated global phishing campaign, termed RecruitTrap, which targets individuals through recruitment-themed lures. The campaign employs fake interview scheduling pages and a Browser-in-the-Browser (BitB) technique to steal Google and Facebook credentials. In more advanced scenarios, it can even relay multi-factor authentication (MFA) prompts in real time. Over two months, CTM360 discovered more than 3,000 phishing URLs associated with this campaign, which impersonated recruiters from over 50 organizations across 14 sectors, predominantly targeting marketing professionals.
The campaign's focus on marketing roles is strategic, as compromised marketing accounts can grant access to critical business resources such as advertising platforms, corporate social media profiles, and customer data. The phishing attack begins with an unsolicited email or meeting invitation that appears to come from a legitimate recruiter. These messages reference the recipient's professional background and invite them to schedule an interview or discussion, leading them into one of two phishing flows.
Victims are directed to either a counterfeit scheduling page resembling Calendly or a brand-specific recruitment portal. Both paths eventually lead to a fake authentication prompt using the BitB technique, which displays a counterfeit login page with a spoofed address bar and padlock. This technique is particularly deceptive on mobile devices, where it may appear as a full-screen login page, making it difficult for users to detect the fraud.
CTM360's analysis of a phishing URL revealed that the page functions as a state machine, guiding victims through various stages such as CAPTCHA, username, password, and multiple two-factor authentication methods. The phishing kit uses a browser-specific session identifier and a persistent Socket.IO channel to manage the victim's journey through the phishing process. The campaign specifically targets corporate accounts by filtering out personal email domains, aiming to capture valuable enterprise identities.
Once victims enter their credentials, attackers use them to sign in to the legitimate service, capturing the MFA code in the process. If successful, the attackers gain an authenticated session, while victims are redirected to a legitimate page to minimize suspicion. The infrastructure supporting this campaign is extensive, with most phishing pages using a Calendly theme and many leveraging Cloudflare to obscure the attackers' servers. The campaign's infrastructure includes numerous registered domains, primarily using the .cfd top-level domain.
To combat such attacks, users are advised to verify unsolicited interview invitations through official company channels and avoid using links provided in suspicious messages. Recognizing a BitB attack involves checking for discrepancies in the address bar and padlock, as well as observing if a password manager fails to autofill expected credentials. Organizations can mitigate risks by adopting phishing-resistant authentication methods, monitoring for lookalike domains, and correlating suspicious emails with unusual sign-in attempts.
RecruitTrap exemplifies how seemingly benign job opportunities can be transformed into scalable identity attacks. The campaign's use of fake browser windows to establish trust, combined with a live backend to execute credential theft and account takeover, highlights the evolving sophistication of phishing tactics. It underscores the importance of vigilance and robust security practices to protect against such threats.


