Recruitment-Themed Phishing Campaign Targets Enterprise Users
ID: f105708d-8b2e-5802-9814-0439804f0da3
STIX ID: report--f105708d-8b2e-5802-9814-0439804f0da3
Feed Name: KnowBe4 Blog
Zimperium reports a widespread phishing campaign (RecruitTrap) using Browser-in-the-Browser attacks to impersonate HR/recruiters and harvest enterprise credentials—particularly targeting job seekers at major companies. The phishing kit filters out personal email domains to focus on corporate accounts, adapts to mobile by showing full-screen fake OAuth login pages, and can capture OAuth tokens and access internal cloud applications, enabling rapid lateral movement within breached organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
