Recruitment Emails Hide BitB Google/Facebook Traps

The Hacker News · High sophistication
Last updated August 17, 2026

Researchers found a large recruitment-themed phishing campaign where victims receive unsolicited interview invites and are sent to fake scheduling or recruitment pages. The pages use “Browser-in-the-Browser” fake login popups to steal Google/Facebook passwords and, in some cases, capture MFA codes in real time to take over accounts.

Key findings

  • CTM360 reported identifying “more than 3,000+ phishing URLs over two months” tied to the campaign it calls “RecruitTrap.”
  • The campaign used recruitment pretexts (interview scheduling / recruitment portals) and impersonated “real recruiters” tied to “more than 50 organizations across 14 sectors.”
  • Victims were pushed into one of two flows: a “counterfeit Calendly-style scheduling page” or a “brand-specific recruitment portal,” both leading to “Continue with Google/Facebook.”
  • Attackers used Browser-in-the-Browser (BitB) to show “a fake authentication popup with a spoofed address bar and padlock.”
  • In advanced cases, the kit relayed MFA: “the fake page then showed the same MFA request and sent the victim’s code back to the attackers.”
  • The phishing kit filtered targets: “The page filtered out personal email domains and only advanced corporate accounts.”

Who’s being targeted

  • Commonly targeted roles: Marketing, HR/Recruiting, All employees (especially active job seekers), IT/Security Service Desk.
  • Affected industries: Recruitment, Technology, Luxury goods, Travel, Marketing/Advertising.
  • Attack channels: email, website.
  • Impersonated: A recruiter at a recognizable organization (using a real recruiter’s identity), Company-branded recruitment portal.

Awareness takeaways

  • Treat unsolicited interview invites as suspicious; verify via official channels and don’t click invite links to ‘schedule’ interviews.
  • Train employees to recognize BitB fake login windows, especially Google sign-in lookalikes, and to check the real website address.
  • Warn that attackers can steal MFA codes in real time; entering an MFA code on an untrusted page can still lead to account takeover.
  • If someone entered credentials/MFA into a suspected recruitment page, respond immediately: change password, revoke sessions, review sign-ins, and alert security.

Red flags to watch for

  • Unsolicited interview invite or meeting request
  • Login prompt appears in a webpage-made popup (BitB) rather than a real Google/Facebook login page
  • You are asked to sign in just to schedule a meeting
  • A recruitment portal that unexpectedly forces Google/Facebook authentication
  • A fake address bar/padlock inside the page (BitB)
  • MFA code requested immediately after entering credentials on an unfamiliar site
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email: "Interview invitation – please schedule a time." Looks like a real recruiter from a big-name company. You click, land on a Calendly-style page or a company-branded portal, and it says: "Continue with Google" or "Continue with Facebook" to book the slot. Here’s the trap: a Browser-in-the-Browser fake popup appears inside the page, showing a tiny "https://accounts.google.com" bar and padlock. It’s not a real window, just part of the site, built to steal your password and even your MFA code in real time. If an unsolicited interview link ever pops a Google or Facebook login, stop and do this: close it, then go to the company’s official careers site or LinkedIn page yourself to confirm the invite.

Similar attacks

Fake Recruiters & Cloud Email Fuel New Phishing

Fake Recruiters & Cloud Email Fuel New Phishing

This roundup describes real-world social engineering where attackers impersonate recruiters on LinkedIn and lure developers into running “coding tests” that install malware. It also outlines active phishing campaigns that abuse trusted cloud services (Google, AWS, Azure, Cloudflare) to send…

September 2, 2026
Phishing Link Could Plant a Rogue ChatGPT Agent

Phishing Link Could Plant a Rogue ChatGPT Agent

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled Workspace Agent inside a company. If an employee was already logged in and had connected apps (like email, Drive, Slack, or Teams), the agent…

July 24, 2026
AI Search Results Turn Into Phishing Traps

AI Search Results Turn Into Phishing Traps

This bulletin describes multiple real-world scams where attackers make fake pages and messages look like routine, trusted experiences (search answers, Google login pop-ups, “giveaways,” and official-sounding calls). Examples include a fake Claude Max giveaway using a convincing fake Google sign-in…

September 24, 2026
Device-Code Phish + Fake Recruiter Interview Lures

Device-Code Phish + Fake Recruiter Interview Lures

This news roundup describes multiple real-world social engineering operations, including a device-code phishing service that stole access to over 12,000 inboxes and a North Korean campaign posing as recruiters to trick developers during fake coding interviews. The attackers used legitimate login…

September 24, 2026
China-Linked Hackers Share Chrome Exploit Lures

China-Linked Hackers Share Chrome Exploit Lures

Proofpoint reported at least four espionage groups (mostly linked to Chinese state intelligence) using the same Chrome zero-day exploit kit (“BlueMoon”) to compromise victims and deliver malware. The operations used believable business and event-themed lures (internship inquiries, procurement…

September 9, 2026
Fake Conferences Fuel OAuth and WhatsApp Phish

Fake Conferences Fuel OAuth and WhatsApp Phish

Google tracked three suspected Russia-linked groups running targeted phishing that abuses real login and authentication features (app passwords, OAuth, and device codes) to get into accounts. The lures often look like legitimate conference or diplomatic invitations, and some campaigns spoof…

August 21, 2026