A sophisticated phishing campaign is targeting high-value corporate credentials through fake job recruitment schemes, leveraging a technique known as browser-in-the-browser (BitB) to deceive victims. The attackers impersonate human resources staff from well-known companies, crafting convincing interview scheduling flows designed to steal corporate passwords.
Researchers tracking the activity observed that the phishing kit employs strict pre-qualification logic, rejecting personal email addresses and only accepting corporate credentials. This deliberate targeting ensures that threat actors gain access to high-value enterprise accounts, which can then provide immediate access to OAuth tokens, internal communications, and cloud applications, facilitating rapid lateral movement within an organization.
While the BitB technique can mimic an entire browser window, including the address bar, on desktop systems to make a fake login page appear genuine, its application differs on mobile devices. On phones, where there is no visible browser window or address bar to begin with, the kit switches to a full-screen fake login page, removing any visual cues a victim might use to verify authenticity.
The campaign has been active for at least a year, with researchers tracking numerous domains impersonating major brands. These domains often follow patterns such as "[company]-careers.com" or "[company]-global.com." The infrastructure supporting these malicious domains shows less variation than might be expected, frequently utilizing the same hosting and cloud providers. Amazon Web Services and SEDO GmbH were identified as common providers at the Autonomous System Number (ASN) level.
Domain blocklists often struggle to keep pace with the rapid registration of new lookalike domains on these shared networks, creating a window of vulnerability before fake sites are flagged. Researchers have published 46 previously undisclosed indicators of compromise related to this activity.
The impersonated brands span a wide range of industries, including e-commerce, luxury goods, aviation, and retail. Companies whose names have been caught up in the scheme include Amazon, Louis Vuitton, Apple, FIFA, Emirates Group, Boeing, Heineken, Deloitte, Central Network Retail Group, and Lego.
Defending against these targeted campaigns necessitates a shift in security focus beyond traditional desktop-centric web gateways. Securing corporate identities at the mobile touchpoint is crucial to mitigate the risks posed by these evolving phishing tactics.






