Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Operation Fake KickOff: Attackers Abuse Recruiters and SaaS to Harvest Work Credentials

0
Medium
Published: 07/15/2026 (07/15/2026, 20:49:51 UTC)
Source: AlienVault OTX General

Description

A sophisticated multi-stage phishing operation has been active since April 2025, systematically exploiting legitimate SaaS platforms and cloud services to steal corporate credentials. The campaign utilizes 232 phishing domains and 80 command-and-control servers, primarily impersonating human resources consulting firms, with Robert Half Inc. and Aquent LLC representing 50% of targeted brands. Attackers leverage legitimate platforms like Salesforce, SendGrid, and Zoho for email delivery, directing victims to fake Calendly interview pages that mimic real recruiter identities. The operation deploys an adversary-in-the-middle toolkit using browser-in-the-box techniques to create replica Google sign-in pages, capable of harvesting credentials and bypassing MFA through email, SMS, Google Authenticator, and prompt notifications. The campaign specifically targets corporate email accounts, filtering out personal providers, with stolen data exfiltrated to Render-hosted servers and Telegram bots.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/15/2026, 22:17:47 UTC

Technical Analysis

This multi-stage phishing operation leverages legitimate SaaS and cloud services to conduct credential theft by impersonating recruiters from well-known HR firms. Attackers use a large infrastructure of phishing domains and command-and-control servers to deliver emails through trusted platforms, increasing the likelihood of victim engagement. Victims are led to fake Calendly pages mimicking real recruiters, where an adversary-in-the-middle toolkit employing browser-in-the-box technology intercepts Google sign-in credentials. This toolkit is capable of bypassing various MFA mechanisms, enabling attackers to harvest corporate credentials effectively. The campaign specifically filters out personal email providers, focusing on corporate accounts, and exfiltrates data to cloud servers and messaging bots for further use.

Potential Impact

The campaign enables attackers to steal corporate credentials, including those protected by MFA, through sophisticated phishing and adversary-in-the-middle techniques. This can lead to unauthorized access to corporate email accounts and potentially other corporate resources, increasing the risk of data breaches, espionage, and further compromise within targeted organizations. The use of legitimate SaaS platforms for email delivery and cloud services for data exfiltration complicates detection and mitigation efforts.

Defensive Guidance

No official patch or fix is applicable as this is a phishing campaign rather than a software vulnerability. Organizations should educate employees about this specific phishing tactic, especially regarding recruitment impersonation and suspicious Calendly links. Implementing advanced email filtering to detect phishing domains and monitoring for unusual login patterns can help. Use of security solutions capable of detecting adversary-in-the-middle browser-in-the-box attacks may reduce risk. Since the campaign bypasses MFA, consider additional protective measures such as hardware security keys and continuous authentication monitoring. Review and restrict third-party SaaS integrations where possible. Refer to the vendor advisory and threat intelligence sources for ongoing updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.intel471.com/blog/operation-fake-kickoff-attackers-abuse-recruiters-and-saas-to-harvest-work-credentials"]
Adversary
O-UNC-038
Pulse Id
6a57f26f4f7b83bede7d73d8
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainfifahr-careers.com
domainadidas-hiring.com

Threat ID: 6a5803ac68715ace4390f60e

Added to database: 07/15/2026, 22:03:24 UTC

Last enriched: 07/15/2026, 22:17:47 UTC

Last updated: 08/25/2026, 22:55:23 UTC

Views: 124

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses