Extended Rapid Response: RecruitTrap Recruit Scams are Targeting Enterprise Credentials on Mobile
Description
RecruitTrap is a sophisticated phishing campaign targeting enterprise credentials by impersonating HR personnel from well-known companies. It uses Browser-in-the-Browser techniques on desktop and full-screen fake login pages on mobile without visible URL indicators. The campaign actively screens victims to focus on corporate accounts, rejecting personal emails. Attackers impersonate multiple global brands and use persistent hosting on Amazon and SEDO networks. Detection of malicious domains is significantly delayed by traditional threat feeds. The campaign facilitates credential harvesting, OAuth token theft, and lateral movement within organizations.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This campaign involves threat actors conducting recruitment-themed phishing attacks to steal enterprise credentials. On desktop, Browser-in-the-Browser techniques create convincing fake login prompts, while mobile devices show full-screen counterfeit login pages lacking URL visibility. The infrastructure filters victims to exclude personal email users, focusing on corporate accounts to maximize impact. Attackers impersonate prominent brands such as Amazon, Louis Vuitton, Apple, FIFA, Emirates, Boeing, Heineken, Deloitte, and Lego. Hosting is primarily on Amazon and SEDO networks, with domains remaining undetected by traditional feeds for periods ranging from days to years. The campaign enables attackers to harvest credentials, steal OAuth tokens, and move laterally within targeted organizations.
Potential Impact
The campaign enables attackers to harvest enterprise user credentials and OAuth tokens, potentially allowing unauthorized access to corporate resources. This can lead to lateral movement within organizations, increasing the risk of data breaches and further compromise of enterprise systems. The targeting of corporate emails and rejection of personal accounts increases the likelihood of successful credential theft from valuable targets. Delayed detection of malicious domains prolongs exposure and risk to organizations.
Defensive Guidance
No official patch or fix applies as this is a phishing campaign. Organizations should educate employees about recruitment-themed phishing and the risks of fake login pages, especially on mobile devices. Use multi-factor authentication to reduce the impact of credential theft. Monitor for suspicious OAuth token activity and implement detection for Browser-in-the-Browser phishing techniques. Employ domain monitoring to identify and block access to known malicious domains listed in threat intelligence feeds. Traditional threat feeds may have detection delays, so proactive threat intelligence integration is recommended.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://zimperium.com/blog/extended-rapid-response-zimperium-identifies-recruittrap-recruit-scams-are-targeting-enterprise-credentials-on-mobile"]
- Pulse Id
- 6a8d043f2b2afd2b5aba604d
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainhbc-careers.com | — | |
domainfifahr-careers.com | — | |
domainmckinsey-careers.com | — | |
domainaa-careers.com | — | |
domainlevis-careers.com | — | |
domainandmore-global.com | — | |
domaincareers.com | — | |
domainexpedia-careers.com | — | |
domaininsulet-careers.com | — | |
domainmondial-relay-global.com | — | |
domainxmtrading-global.com | — |
Threat ID: 6a8d73d1acd9273b490ff6ed
Added to database: 08/25/2026, 10:52:01 UTC
Last enriched: 09/10/2026, 20:04:17 UTC
Last updated: 10/02/2026, 20:49:23 UTC
Views: 95
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.