RecruitTrap recruitment-themed phishing campaign
Campaign
Summary
Hide ▲
Show ▼
The RecruitTrap campaign used fake recruiter outreach and BitB login pages to steal Google and Facebook credentials and relay MFA prompts in real time. It spanned more than 3,000 phishing URLs over two months and impersonated recruiters tied to 50+ organizations across 14 sectors. Marketing professionals were the most common targets, increasing the risk of account takeover for people with access to advertising, social media, and customer-facing services. The shared infrastructure and rapid rebranding made the operation easy to redeploy against new victims.
Related Happenings
LogoKit real-time per-victim phishing campaign
Campaign
H score35
First: 29.07.2026 19:00
Last: 29.07.2026 19:00
Sources 1
About this happening:
The LogoKit phishing-as-a-service campaign now builds a unique login page per victim in real time, making credential theft harder to detect and block. It uses live scree...
LogoKit real-time per-victim phishing campaign
CampaignAbout this happening: The LogoKit phishing-as-a-service campaign now builds a unique login page per victim in real time, making credential theft harder to detect and block. It uses live scree...
BlueNoroff ClickFix-style Zoom and Microsoft Teams phishing campaign
Campaign
H score38
First: 24.07.2026 18:12
Last: 24.07.2026 18:12
Sources 1
About this happening:
BlueNoroff's ClickFix-style phishing campaign is using typosquatted Zoom and Microsoft Teams domains to deliver malware and steal Telegram sessions from high-value cry...
BlueNoroff ClickFix-style Zoom and Microsoft Teams phishing campaign
CampaignAbout this happening: BlueNoroff's ClickFix-style phishing campaign is using typosquatted Zoom and Microsoft Teams domains to deliver malware and steal Telegram sessions from high-value cry...
Q2 2026 brand phishing expands to ChatGPT impersonation
Trend
H score35
First: 24.07.2026 14:15
Last: 24.07.2026 14:15
Sources 1
About this happening:
Phishing impersonation of technology brands rose in Q2 2026, with ChatGPT entering the top 10 of most impersonated brands for the first time and signaling growing atta...
Q2 2026 brand phishing expands to ChatGPT impersonation
TrendAbout this happening: Phishing impersonation of technology brands rose in Q2 2026, with ChatGPT entering the top 10 of most impersonated brands for the first time and signaling growing atta...
GPPStorm Google Partners enrollment phishing campaign
Campaign
H score33
First: 13.07.2026 16:03
Last: 13.07.2026 16:03
Sources 1
About this happening:
GPPStorm is a phishing campaign that uses bogus Google Partners and Google Premier Partner enrollment workflows to push recipients to a fake Google sign-in page and st...
GPPStorm Google Partners enrollment phishing campaign
CampaignAbout this happening: GPPStorm is a phishing campaign that uses bogus Google Partners and Google Premier Partner enrollment workflows to push recipients to a fake Google sign-in page and st...
Pink new extortion brand within The Com
Threat Actor Meta
H score31
First: 08.07.2026 19:47
Last: 08.07.2026 19:47
Sources 1
About this happening:
Pink is an extortion brand linked to UNC6671 that is being used in vishing and phishing campaigns against enterprise users. Google Threat Intelligence Group says *...
Pink new extortion brand within The Com
Threat Actor MetaAbout this happening: Pink is an extortion brand linked to UNC6671 that is being used in vishing and phishing campaigns against enterprise users. Google Threat Intelligence Group says *...
Timeline
-
14.08.2026 13:57 2 articles · 3d ago
RecruitTrap uses fake recruiter interviews to steal Google and Facebook logins
Initial DisclosureCTM360 detailed RecruitTrap, a global recruitment-themed phishing campaign that used fake interview scheduling pages and Browser-in-the-Browser windows to steal Google and Facebook credentials, relay MFA prompts in real time, and impersonate recruiters tied to more than 50 organizations across 14 sectors. The activity spanned more than 3,000 phishing URLs over two months, and marketing professionals were the most common targets.
Show sources
- CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps — thehackernews.com — 14.08.2026 13:57
- CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps — thehackernews.com — 14.08.2026 13:57