Recruitment Emails Hide BitB Google/Facebook Traps

The Hacker News · High sophistication
Last updated August 17, 2026

Researchers found a large recruitment-themed phishing campaign where victims receive unsolicited interview invites and are sent to fake scheduling or recruitment pages. The pages use “Browser-in-the-Browser” fake login popups to steal Google/Facebook passwords and, in some cases, capture MFA codes in real time to take over accounts.

Key findings

  • CTM360 reported identifying “more than 3,000+ phishing URLs over two months” tied to the campaign it calls “RecruitTrap.”
  • The campaign used recruitment pretexts (interview scheduling / recruitment portals) and impersonated “real recruiters” tied to “more than 50 organizations across 14 sectors.”
  • Victims were pushed into one of two flows: a “counterfeit Calendly-style scheduling page” or a “brand-specific recruitment portal,” both leading to “Continue with Google/Facebook.”
  • Attackers used Browser-in-the-Browser (BitB) to show “a fake authentication popup with a spoofed address bar and padlock.”
  • In advanced cases, the kit relayed MFA: “the fake page then showed the same MFA request and sent the victim’s code back to the attackers.”
  • The phishing kit filtered targets: “The page filtered out personal email domains and only advanced corporate accounts.”

Who’s being targeted

  • Commonly targeted roles: Marketing, HR/Recruiting, All employees (especially active job seekers), IT/Security Service Desk.
  • Affected industries: Recruitment, Technology, Luxury goods, Travel, Marketing/Advertising.
  • Attack channels: email, website.
  • Impersonated: A recruiter at a recognizable organization (using a real recruiter’s identity), Company-branded recruitment portal.

Awareness takeaways

  • Treat unsolicited interview invites as suspicious; verify via official channels and don’t click invite links to ‘schedule’ interviews.
  • Train employees to recognize BitB fake login windows, especially Google sign-in lookalikes, and to check the real website address.
  • Warn that attackers can steal MFA codes in real time; entering an MFA code on an untrusted page can still lead to account takeover.
  • If someone entered credentials/MFA into a suspected recruitment page, respond immediately: change password, revoke sessions, review sign-ins, and alert security.

Red flags to watch for

  • Unsolicited interview invite or meeting request
  • Login prompt appears in a webpage-made popup (BitB) rather than a real Google/Facebook login page
  • You are asked to sign in just to schedule a meeting
  • A recruitment portal that unexpectedly forces Google/Facebook authentication
  • A fake address bar/padlock inside the page (BitB)
  • MFA code requested immediately after entering credentials on an unfamiliar site
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email: "Interview invitation – please schedule a time." Looks like a real recruiter from a big-name company. You click, land on a Calendly-style page or a company-branded portal, and it says: "Continue with Google" or "Continue with Facebook" to book the slot. Here’s the trap: a Browser-in-the-Browser fake popup appears inside the page, showing a tiny "https://accounts.google.com" bar and padlock. It’s not a real window, just part of the site, built to steal your password and even your MFA code in real time. If an unsolicited interview link ever pops a Google or Facebook login, stop and do this: close it, then go to the company’s official careers site or LinkedIn page yourself to confirm the invite.

Similar attacks

Phishing Link Could Plant a Rogue ChatGPT Agent

Phishing Link Could Plant a Rogue ChatGPT Agent

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled Workspace Agent inside a company. If an employee was already logged in and had connected apps (like email, Drive, Slack, or Teams), the agent…

July 24, 2026
Fake Voicemail Alert Steals Google Passwords

Fake Voicemail Alert Steals Google Passwords

A real phishing campaign is tricking employees with a “missed voicemail” message that claims they have a new audio message. Clicking “Play Audio” sends victims through multiple trusted-looking redirects and ends on a fake Google sign-in page that captures Google Workspace credentials, potentially…

August 12, 2026
Fake Zoom/Teams Calls Used to Steal Crypto Wallets

Fake Zoom/Teams Calls Used to Steal Crypto Wallets

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims into “updating” Zoom/Teams and running malicious commands. The phishing kit also fingerprints the victim’s browser to identify installed…

July 24, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented example used a fake “ChatGPT Plus payment failure” notice that sent victims to a fraudulent payment page designed to capture full credit…

July 28, 2026
Hotel Wi‑Fi DNS Scam Steals Microsoft 365 Logins

Hotel Wi‑Fi DNS Scam Steals Microsoft 365 Logins

Attackers are taking over hotel and conference Wi‑Fi gateways and changing DNS settings so travelers are silently redirected to fake Microsoft 365 sign-in pages. Victims are then tricked into completing a device-code login that grants attackers a legitimate session token, often bypassing MFA. This…

July 28, 2026