logo

Recruitment-Themed Phishing Campaign Targets Enterprise Users

ID: f105708d-8b2e-5802-9814-0439804f0da3

STIX ID: report--f105708d-8b2e-5802-9814-0439804f0da3

Feed Name: KnowBe4 Blog

Threat Score
70/100

Date Published: 2026-09-02

Date Updated: 2026-09-05

Author: KnowBe4 Team

...
...

Zimperium reports a widespread phishing campaign (RecruitTrap) using Browser-in-the-Browser attacks to impersonate HR/recruiters and harvest enterprise credentials—particularly targeting job seekers at major companies. The phishing kit filters out personal email domains to focus on corporate accounts, adapts to mobile by showing full-screen fake OAuth login pages, and can capture OAuth tokens and access internal cloud applications, enabling rapid lateral movement within breached organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.