CTM360 Report Reveals Browser In Browser Recruitment Phishing Campaign Targeting Enterprise Accounts

Published:

Cybersecurity researchers at CTM360 have uncovered a large scale recruitment themed phishing campaign that uses fake interview scheduling pages and Browser In Browser (BitB) credential traps to steal Google and Facebook login credentials from victims. Detailed in a report titled “RecruitTrap,” the campaign was observed over a two month period and involved more than 3,000 phishing URLs impersonating recruitment processes from over 50 organizations across 14 different industries. According to CTM360, marketing professionals represented the largest group of targeted victims, likely because compromised marketing accounts can provide attackers with access to advertising platforms, corporate social media accounts, customer information, email systems and other business critical resources. The researchers explained that the campaign demonstrates how familiar hiring processes can be transformed into effective identity theft operations through realistic branding and sophisticated phishing techniques. The complete report is available here.

The attack begins with an unsolicited email or meeting invitation that appears to originate from a legitimate recruiter representing a recognizable organization. These messages typically reference the recipient’s professional experience and invite them to schedule an interview or introductory meeting. Victims are then directed to one of two phishing flows. The first imitates a Calendly style interview scheduling page that closely mirrors legitimate branding and may even include the names, job titles and publicly available photographs of real recruiters. The second presents a counterfeit company recruitment portal where users are asked to choose an interview date and submit basic contact details. Both paths eventually direct victims to a “Continue with Google” or “Continue with Facebook” login option. Instead of displaying a genuine authentication window, the phishing page launches a Browser In Browser popup that mimics an authentic browser login window complete with a fake address bar and security padlock. On mobile devices, this deceptive interface may appear as a full screen login page, making it even more difficult for users to identify the fraud.

CTM360’s technical analysis revealed that the phishing platform functions as a sophisticated state driven application rather than a simple credential collection form. Built using Svelte and SvelteKit technologies, the phishing kit guides victims through multiple authentication stages including CAPTCHA verification, username entry, password submission and several multi factor authentication methods such as one time passwords, phone number matching and suffix verification. The campaign stores browser specific session identifiers while maintaining a persistent Socket.IO communication channel that enables attackers to control the authentication process in real time. The phishing platform also filters out personal email services, allowing only corporate email accounts to proceed, thereby focusing attacks on higher value enterprise identities. Once credentials are entered, attackers immediately attempt to authenticate with the legitimate service and relay any MFA prompts back to the victim. If authentication succeeds, attackers gain an authenticated session while victims may be redirected to a legitimate Calendly page to reduce suspicion and avoid detection.

CTM360 found that approximately 96 percent of the identified phishing sites used a Calendly themed interface, with many hiding their backend infrastructure behind Cloudflare services. Among 813 deduplicated registered domains, the .cfd top level domain accounted for 40 percent of registrations, followed by .com, .info, .works and .work. The researchers also identified 116 unique hosts supporting the brand specific recruitment portals, with over half of them hosted on AWS EC2 infrastructure, indicating the use of shared deployment environments that allow attackers to rapidly rebrand campaigns by changing employer names, recruiter identities, logos and authentication providers while retaining the same attack framework. CTM360 advises users to independently verify unsolicited interview invitations through official company channels and access career portals directly rather than clicking embedded links. The researchers also recommend confirming that Google authentication occurs only through legitimate Google domains, using phishing resistant authentication methods such as passkeys or hardware backed WebAuthn, monitoring for suspicious recruitment domains and immediately changing passwords, revoking active sessions and notifying security teams if credentials or MFA codes have been entered into a suspected phishing page. The complete technical analysis can be accessed here.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Related articles

spot_img