Fake Job Interview Pages Used to Steal Google and Facebook Logins in Global Phishing Campaign
Cybersecurity researchers at CTM360 have uncovered a large-scale phishing campaign, dubbed 'RecruitTrap', that targets job seekers with fake interview scheduling pages. The campaign uses a technique known as Browser-in-the-Browser (BitB), which creates a convincing fake pop-up login window that mimics a real browser sign-in prompt for services like Google or Facebook.
Victims who believe they are logging in to confirm an interview are instead handing their credentials directly to attackers. In more advanced versions of the attack, criminals are also able to intercept and relay multi-factor authentication (MFA) prompts in real time, allowing them to bypass this extra layer of security and gain full access to victims' accounts.
With more than 3,000 phishing URLs identified globally, this campaign highlights how attackers are exploiting the stress and urgency around job hunting to trick even cautious users. Because the fake login windows can closely resemble genuine ones, traditional advice like 'check the URL' becomes harder for victims to apply, making awareness of this specific tactic important for anyone applying for jobs online or handling recruitment on behalf of a business.