Fake Recruiters & Cloud Email Fuel New Phishing

About DFIR · High sophistication
Last updated September 2, 2026

This roundup describes real-world social engineering where attackers impersonate recruiters on LinkedIn and lure developers into running “coding tests” that install malware. It also outlines active phishing campaigns that abuse trusted cloud services (Google, AWS, Azure, Cloudflare) to send convincing emails and route victims to fake Microsoft 365 login pages, including adversary-in-the-middle kits designed to bypass MFA.

Key findings

  • Iran-linked actors (Mirage Kitten / UNC1549) used fake recruiter outreach on LinkedIn and job platforms to lure developers into downloading and running trojanized “coding test” archives.
  • Some “coding tests” used time pressure and single-use codes, and even banned AI coding assistants to reduce the chance victims would notice malicious code.
  • A separate phishing campaign routed lures through trusted cloud services (Google Cloud, AWS S3, Azure, Firebase, Cloudflare) to look legitimate and pass email authentication checks.
  • Victims were funneled through CAPTCHA gates to fake Microsoft 365 login pages; adversary-in-the-middle tooling can capture session tokens to bypass MFA.

Who’s being targeted

  • Commonly targeted roles: Developers, Engineering leadership, Finance and Accounting, IT / Identity and Access Management (IAM), Security awareness program participants.
  • Affected industries: Finance, Aviation, Aerospace, Fintech, Software development.
  • Attack channels: linkedin, email, website.
  • Impersonated: Recruiter / hiring team for an aviation, aerospace, or fintech employer, Google Cloud / Microsoft 365 sign-in workflow.

Awareness takeaways

  • Treat unsolicited recruiter messages and “coding tests” as high risk, verify the recruiter and do not run unknown projects on your work device.
  • Be suspicious of urgent hiring steps that try to reduce scrutiny (time pressure, single-use codes, or bans on tools that could help you review code).
  • Don’t trust an email just because it comes from a well-known cloud domain; attackers can abuse legitimate cloud email features to send convincing lures.
  • MFA isn’t a guarantee if you’re tricked into logging into a fake page, adversary-in-the-middle phishing can steal session tokens.

Red flags to watch for

  • Unsolicited recruiter approach pushing you to run a project locally
  • Time pressure and “single-use access codes” to rush execution
  • Instructions that ban AI coding assistants (attempting to reduce scrutiny)
  • Unexpected CAPTCHA gate before a corporate login
  • Login page hosted on cloud storage (e.g., AWS S3) instead of your organization’s normal sign-in domain
  • Email appears to come from a trusted cloud domain but is unrelated to an expected business process
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

A LinkedIn recruiter sends you a "coding test" zip and a Google email asks you to log into Microsoft 365. Both can be traps. Iran-linked Mirage Kitten has posed as aviation and fintech recruiters on LinkedIn, pushing devs to run trojanized "coding tests" that drop NodeRabbit and PollCat malware on Windows, macOS, and Linux. At the same time, phishers abuse Google Cloud and AWS so emails pass SPF, DKIM, DMARC, then funnel you through a random CAPTCHA to a fake Microsoft 365 page that can even steal MFA session tokens. Aha moment: if a stranger recruiter wants you to run code, or a cloud email sends you through a CAPTCHA to log in, stop and verify out-of-band before you open the file or type your password.

Similar attacks

Fake Recruiter Lure Drops NodeRabbit RAT

Fake Recruiter Lure Drops NodeRabbit RAT

Researchers tied Mirage Kitten to a job-recruiting scam that targets developers via LinkedIn and job platforms. Victims are sent a “technical assessment” ZIP file hosted on legitimate cloud storage; running the project silently installs a remote-access trojan (NodeRabbit) that lets attackers…

September 1, 2026
Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Researchers say the North Korea-linked Lazarus group ran “Operation Dream Job,” posing as recruiters and sending fake job offers to lure targets into downloading trojanized PDF tools and opening booby-trapped PDFs. The campaign focused largely on defense-related organizations and used both a…

August 12, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
Fake LinkedIn Coding Tests Deliver Mirage Kitten Malware

Fake LinkedIn Coding Tests Deliver Mirage Kitten Malware

Kaspersky reported that Iran-linked APT Mirage Kitten approached software engineers on LinkedIn using fake recruiter personas and sent “coding challenges” that were actually trojanized projects. The lure used legitimate-looking cloud hosting (Amazon S3) and even instructed victims not to use AI…

September 2, 2026
Fake Conferences Fuel OAuth and WhatsApp Phish

Fake Conferences Fuel OAuth and WhatsApp Phish

Google tracked three suspected Russia-linked groups running targeted phishing that abuses real login and authentication features (app passwords, OAuth, and device codes) to get into accounts. The lures often look like legitimate conference or diplomatic invitations, and some campaigns spoof…

August 21, 2026
Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026