Operation Fake KickOff: Attackers Abuse Recruiters and SaaS to Harvest Work Credentials
A sophisticated multi-stage phishing operation has been active since April 2025, systematically exploiting legitimate SaaS platforms and cloud services to steal corporate credentials. The campaign utilizes 232 phishing domains and 80 command-and-control servers, primarily impersonating human resources consulting firms, with Robert Half Inc. and Aquent LLC representing 50% of targeted brands. Attackers leverage legitimate platforms like Salesforce, SendGrid, and Zoho for email delivery, directing victims to fake Calendly interview pages that mimic real recruiter identities. The operation deploys an adversary-in-the-middle toolkit using browser-in-the-box techniques to create replica Google sign-in pages, capable of harvesting credentials and bypassing MFA through email, SMS, Google Authenticator, and prompt notifications. The campaign specifically targets corporate email accounts, filtering out personal providers, with stolen data exfiltrated to Render-hosted servers and Telegram bots.
AI Analysis
Technical Summary
This multi-stage phishing operation leverages legitimate SaaS and cloud services to conduct credential theft by impersonating recruiters from well-known HR firms. Attackers use a large infrastructure of phishing domains and command-and-control servers to deliver emails through trusted platforms, increasing the likelihood of victim engagement. Victims are led to fake Calendly pages mimicking real recruiters, where an adversary-in-the-middle toolkit employing browser-in-the-box technology intercepts Google sign-in credentials. This toolkit is capable of bypassing various MFA mechanisms, enabling attackers to harvest corporate credentials effectively. The campaign specifically filters out personal email providers, focusing on corporate accounts, and exfiltrates data to cloud servers and messaging bots for further use.
Potential Impact
The campaign enables attackers to steal corporate credentials, including those protected by MFA, through sophisticated phishing and adversary-in-the-middle techniques. This can lead to unauthorized access to corporate email accounts and potentially other corporate resources, increasing the risk of data breaches, espionage, and further compromise within targeted organizations. The use of legitimate SaaS platforms for email delivery and cloud services for data exfiltration complicates detection and mitigation efforts.
Mitigation Recommendations
No official patch or fix is applicable as this is a phishing campaign rather than a software vulnerability. Organizations should educate employees about this specific phishing tactic, especially regarding recruitment impersonation and suspicious Calendly links. Implementing advanced email filtering to detect phishing domains and monitoring for unusual login patterns can help. Use of security solutions capable of detecting adversary-in-the-middle browser-in-the-box attacks may reduce risk. Since the campaign bypasses MFA, consider additional protective measures such as hardware security keys and continuous authentication monitoring. Review and restrict third-party SaaS integrations where possible. Refer to the vendor advisory and threat intelligence sources for ongoing updates.
Indicators of Compromise
- domain: fifahr-careers.com
- domain: adidas-hiring.com
Operation Fake KickOff: Attackers Abuse Recruiters and SaaS to Harvest Work Credentials
Description
A sophisticated multi-stage phishing operation has been active since April 2025, systematically exploiting legitimate SaaS platforms and cloud services to steal corporate credentials. The campaign utilizes 232 phishing domains and 80 command-and-control servers, primarily impersonating human resources consulting firms, with Robert Half Inc. and Aquent LLC representing 50% of targeted brands. Attackers leverage legitimate platforms like Salesforce, SendGrid, and Zoho for email delivery, directing victims to fake Calendly interview pages that mimic real recruiter identities. The operation deploys an adversary-in-the-middle toolkit using browser-in-the-box techniques to create replica Google sign-in pages, capable of harvesting credentials and bypassing MFA through email, SMS, Google Authenticator, and prompt notifications. The campaign specifically targets corporate email accounts, filtering out personal providers, with stolen data exfiltrated to Render-hosted servers and Telegram bots.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This multi-stage phishing operation leverages legitimate SaaS and cloud services to conduct credential theft by impersonating recruiters from well-known HR firms. Attackers use a large infrastructure of phishing domains and command-and-control servers to deliver emails through trusted platforms, increasing the likelihood of victim engagement. Victims are led to fake Calendly pages mimicking real recruiters, where an adversary-in-the-middle toolkit employing browser-in-the-box technology intercepts Google sign-in credentials. This toolkit is capable of bypassing various MFA mechanisms, enabling attackers to harvest corporate credentials effectively. The campaign specifically filters out personal email providers, focusing on corporate accounts, and exfiltrates data to cloud servers and messaging bots for further use.
Potential Impact
The campaign enables attackers to steal corporate credentials, including those protected by MFA, through sophisticated phishing and adversary-in-the-middle techniques. This can lead to unauthorized access to corporate email accounts and potentially other corporate resources, increasing the risk of data breaches, espionage, and further compromise within targeted organizations. The use of legitimate SaaS platforms for email delivery and cloud services for data exfiltration complicates detection and mitigation efforts.
Defensive Guidance
No official patch or fix is applicable as this is a phishing campaign rather than a software vulnerability. Organizations should educate employees about this specific phishing tactic, especially regarding recruitment impersonation and suspicious Calendly links. Implementing advanced email filtering to detect phishing domains and monitoring for unusual login patterns can help. Use of security solutions capable of detecting adversary-in-the-middle browser-in-the-box attacks may reduce risk. Since the campaign bypasses MFA, consider additional protective measures such as hardware security keys and continuous authentication monitoring. Review and restrict third-party SaaS integrations where possible. Refer to the vendor advisory and threat intelligence sources for ongoing updates.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.intel471.com/blog/operation-fake-kickoff-attackers-abuse-recruiters-and-saas-to-harvest-work-credentials"]
- Adversary
- O-UNC-038
- Pulse Id
- 6a57f26f4f7b83bede7d73d8
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainfifahr-careers.com | — | |
domainadidas-hiring.com | — |
Threat ID: 6a5803ac68715ace4390f60e
Added to database: 07/15/2026, 22:03:24 UTC
Last enriched: 07/15/2026, 22:17:47 UTC
Last updated: 08/25/2026, 22:55:23 UTC
Views: 124
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.