LIVE · cybersecurity feed
Live wire
phishing

Phishing poses as big-brand job interview to steal Google accounts

A phishing campaign is impersonating more than 30 well-known brands, including Adobe, Netflix, Coca-Cola, and OpenAI, in fake job interviews to steal Google account credentials from marketing professionals. [...]

zeroday.news · 26d ago

A sophisticated phishing campaign is targeting marketing professionals by impersonating over 30 major brands in fake job interview invitations, aiming to steal their Google account credentials. The operation leverages legitimate cloud services and a domain linked to Salesforce Marketing Cloud to build trust before redirecting victims to a malicious landing page.

The threat actor is employing a tactic of impersonating well-known companies, including airlines like American Airlines and Delta Air Lines, food and beverage giants such as Coca-Cola and PepsiCo, and tech companies like Adobe and OpenAI. Other impersonated brands span apparel, luxury goods, staffing, consulting, hospitality, marketing, entertainment, and sports sectors. To enhance credibility, the campaign uses the names and photographs of actual recruiters from these impersonated organizations.

The phishing emails, which appear to originate from the PeopleForce human resources platform, are designed to look like genuine recruitment outreach for marketing roles. However, the embedded links employ a technique of nested redirects. These links initially point to a domain associated with Salesforce Marketing Cloud, a service that evolved from the ExactTarget marketing automation platform. From there, the chain continues through Wise Agent, a real estate CRM software, before finally landing on the attacker-controlled phishing page.

Researchers have observed that this campaign has been active for at least five months. Early iterations of the phishing emails used Outlook addresses that included the name of the company being impersonated. For instance, an email posing as a recruiter from Adidas, named Paulina Manzo, invited recipients to schedule a meeting about a potential role.

When a potential victim clicks on a link to schedule a meeting, they are directed to a fake landing page, such as one impersonating Adidas at `adidas-hiring[.]com`. To proceed, the user is prompted to sign into their Google account.

The campaign employs a "browser-in-the-browser" (BitB) attack technique. When the user clicks a "Continue with Google" button on the phishing page, a fake Google sign-in pop-up appears. This pop-up, while appearing to be a legitimate browser window, is actually rendered within the phishing page using HTML and CSS, mimicking the appearance of a real Google authentication prompt. This allows the attacker to capture the user's Google login credentials.

It remains unclear how the threat actor gained access to the legitimate platforms used in the redirect chain. The abuse of these services does not necessarily indicate a compromise of the platforms themselves. Possible methods include creating legitimate accounts specifically for the campaign or utilizing compromised login credentials to configure the redirect sequences and the final landing page. A list of domains identified in this phishing campaign is available in the analysis by Will Thomas.

Security professionals are advised to test their defenses proactively. The campaign highlights the importance of robust security measures to detect and prevent such sophisticated phishing attacks, especially those that bypass traditional security controls by using legitimate services in their attack chain.

phishingai
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.