Skip to main content

Extended Rapid Response: RecruitTrap Recruit Scams are Targeting Enterprise Credentials on Mobile

0
Medium
Published: 08/25/2026 (08/25/2026, 02:55:59 UTC)
Source: AlienVault OTX General

Description

RecruitTrap is a sophisticated phishing campaign targeting enterprise credentials by impersonating HR personnel from well-known companies. It uses Browser-in-the-Browser techniques on desktop and full-screen fake login pages on mobile without visible URL indicators. The campaign actively screens victims to focus on corporate accounts, rejecting personal emails. Attackers impersonate multiple global brands and use persistent hosting on Amazon and SEDO networks. Detection of malicious domains is significantly delayed by traditional threat feeds. The campaign facilitates credential harvesting, OAuth token theft, and lateral movement within organizations.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 20:04:17 UTC

Technical Analysis

This campaign involves threat actors conducting recruitment-themed phishing attacks to steal enterprise credentials. On desktop, Browser-in-the-Browser techniques create convincing fake login prompts, while mobile devices show full-screen counterfeit login pages lacking URL visibility. The infrastructure filters victims to exclude personal email users, focusing on corporate accounts to maximize impact. Attackers impersonate prominent brands such as Amazon, Louis Vuitton, Apple, FIFA, Emirates, Boeing, Heineken, Deloitte, and Lego. Hosting is primarily on Amazon and SEDO networks, with domains remaining undetected by traditional feeds for periods ranging from days to years. The campaign enables attackers to harvest credentials, steal OAuth tokens, and move laterally within targeted organizations.

Potential Impact

The campaign enables attackers to harvest enterprise user credentials and OAuth tokens, potentially allowing unauthorized access to corporate resources. This can lead to lateral movement within organizations, increasing the risk of data breaches and further compromise of enterprise systems. The targeting of corporate emails and rejection of personal accounts increases the likelihood of successful credential theft from valuable targets. Delayed detection of malicious domains prolongs exposure and risk to organizations.

Defensive Guidance

No official patch or fix applies as this is a phishing campaign. Organizations should educate employees about recruitment-themed phishing and the risks of fake login pages, especially on mobile devices. Use multi-factor authentication to reduce the impact of credential theft. Monitor for suspicious OAuth token activity and implement detection for Browser-in-the-Browser phishing techniques. Employ domain monitoring to identify and block access to known malicious domains listed in threat intelligence feeds. Traditional threat feeds may have detection delays, so proactive threat intelligence integration is recommended.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://zimperium.com/blog/extended-rapid-response-zimperium-identifies-recruittrap-recruit-scams-are-targeting-enterprise-credentials-on-mobile"]
Pulse Id
6a8d043f2b2afd2b5aba604d

Indicators of Compromise

Domain

ValueDescriptionCopy
domainhbc-careers.com
—
domainfifahr-careers.com
—
domainmckinsey-careers.com
—
domainaa-careers.com
—
domainlevis-careers.com
—
domainandmore-global.com
—
domaincareers.com
—
domainexpedia-careers.com
—
domaininsulet-careers.com
—
domainmondial-relay-global.com
—
domainxmtrading-global.com
—

Threat ID: 6a8d73d1acd9273b490ff6ed

Added to database: 08/25/2026, 10:52:01 UTC

Last enriched: 09/10/2026, 20:04:17 UTC

Last updated: 10/02/2026, 20:49:23 UTC

Views: 95

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses