Extended Rapid Response: RecruitTrap Recruit Scams are Targeting Enterprise Credentials on Mobile
Threat actors are conducting sophisticated recruitment-themed phishing campaigns by impersonating HR personnel from prominent companies. The attacks leverage Browser-in-the-Browser techniques on desktop, while mobile devices display full-screen counterfeit login pages without visible URL indicators. The malicious infrastructure actively screens victims, rejecting personal emails to specifically target corporate credentials and enterprise access. Analysis reveals persistent hosting patterns primarily using Amazon and SEDO networks, with attackers impersonating brands including Amazon, Louis Vuitton, Apple, FIFA, Emirates, Boeing, Heineken, Deloitte, and Lego. Traditional threat feeds show significant delays in detecting these domains, with detection gaps ranging from 7 days to over 6 years. The campaign enables credential harvesting, OAuth token theft, and lateral movement within organizations.
Indicators of Compromise
- domain: hbc-careers.com
- domain: fifahr-careers.com
- domain: mckinsey-careers.com
- domain: aa-careers.com
- domain: levis-careers.com
- domain: andmore-global.com
- domain: careers.com
- domain: expedia-careers.com
- domain: insulet-careers.com
- domain: mondial-relay-global.com
- domain: xmtrading-global.com
Extended Rapid Response: RecruitTrap Recruit Scams are Targeting Enterprise Credentials on Mobile
Description
Threat actors are conducting sophisticated recruitment-themed phishing campaigns by impersonating HR personnel from prominent companies. The attacks leverage Browser-in-the-Browser techniques on desktop, while mobile devices display full-screen counterfeit login pages without visible URL indicators. The malicious infrastructure actively screens victims, rejecting personal emails to specifically target corporate credentials and enterprise access. Analysis reveals persistent hosting patterns primarily using Amazon and SEDO networks, with attackers impersonating brands including Amazon, Louis Vuitton, Apple, FIFA, Emirates, Boeing, Heineken, Deloitte, and Lego. Traditional threat feeds show significant delays in detecting these domains, with detection gaps ranging from 7 days to over 6 years. The campaign enables credential harvesting, OAuth token theft, and lateral movement within organizations.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://zimperium.com/blog/extended-rapid-response-zimperium-identifies-recruittrap-recruit-scams-are-targeting-enterprise-credentials-on-mobile"]
- Adversary
- null
- Pulse Id
- 6a8d043f2b2afd2b5aba604d
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainhbc-careers.com | — | |
domainfifahr-careers.com | — | |
domainmckinsey-careers.com | — | |
domainaa-careers.com | — | |
domainlevis-careers.com | — | |
domainandmore-global.com | — | |
domaincareers.com | — | |
domainexpedia-careers.com | — | |
domaininsulet-careers.com | — | |
domainmondial-relay-global.com | — | |
domainxmtrading-global.com | — |
Threat ID: 6a8d73d1acd9273b490ff6ed
Added to database: 08/25/2026, 10:52:01 UTC
Last updated: 08/25/2026, 13:52:45 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.