CTM360 Finds More Than 3,000 Recruitment Phishing URLs Using Browser-in-the
443/69 monday, August 17, 2026
Cybersecurity researchers from CTM360 have published a report on a large-scale phishing campaign named RecruitTrap, which uses fake recruitment processes or job interview invitations to steal Google and Facebook credentials. In some cases, the campaign can also relay Multi-Factor Authentication (MFA) requests in real time. CTM360 stated that it identified more than 3,000 phishing URLs within a two-month period. The campaign impersonated recruiters and hiring processes from more than 50 organizations across 14 sectors. The most frequently targeted group was marketing personnel, as their accounts may have access to advertising platforms, corporate social media accounts, customer data, email, and other critical business services.
The attack typically begins with an unsolicited email or meeting invitation that appears to come from a recruiter at a trusted organization and references the recipient’s work history before inviting them to schedule an interview or informal discussion. Victims are redirected to one of two types of fake websites: a scheduling page impersonating Calendly or a branded recruitment portal impersonating a legitimate organization. Both routes lead to a “Continue with Google/Facebook” button, after which the attackers use the Browser-in-the-Browser (BitB) technique to display a fake login window with a forged address bar and padlock icon, making victims believe they are interacting with a legitimate login page. On mobile devices, the phishing page may appear as a full-screen fake login page. CTM360’s analysis also found that the phishing kit operates as a state machine rather than a simple credential-harvesting form, with stages for CAPTCHA, username, password, and multiple MFA methods such as OTP, phone number matching, and suffix verification. It also uses Socket.IO to allow the backend to control what the victim sees in real time.
CTM360 stated that approximately 96% of the phishing pages used a Calendly-themed design, while many also used Cloudflare to hide the attackers’ real servers. Brand-specific fake recruitment portals were observed across 116 different hosts and shared common infrastructure. The most commonly observed top-level domains (TLDs) included .cfd, .com, .info, .works, and .work. The campaign can also rapidly switch brands by changing only the organization name, recruiter identity, background, slogan, and authentication provider, while retaining the same 30-minute scheduling flow and login process. Users should verify unsolicited interview invitations directly through the organization’s official channels, avoid clicking links in messages, and note that a legitimate Google Sign-in page should be hosted on the accounts.google.com domain. Organizations should adopt phishing-resistant authentication methods such as passkeys or hardware-backed WebAuthn. If users have entered credentials or MFA codes on a suspicious page, they should immediately change their passwords, revoke sessions and tokens, review sign-in activity, and inspect mailbox rules and OAuth grants.
Source: https://thehackernews.com/2026/08/ctm360-uncovers-over-3000-recruitment.html
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.