RecruitTrap fake recruiter corporate credential phishing campaign
Campaign
Summary
Hide ▲
Show ▼
RecruitTrap is a targeted phishing campaign impersonating employers and recruiters to steal corporate credentials on mobile devices. The operation uses full-screen counterfeit login pages and pre-qualification checks to filter out personal email addresses, which increases the chance that stolen logins map to enterprise accounts. Compromised access could expose OAuth tokens, internal communications, and cloud applications.
Related Happenings
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor Meta
H score37
First: 09.07.2026 17:39
Last: 09.07.2026 17:39
Sources 1
About this happening:
Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor MetaAbout this happening: Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
AccountDumpling Google AppSheet Facebook phishing campaign
Campaign
H score31
First: 01.05.2026 21:09
Last: 01.05.2026 21:09
Sources 1
About this happening:
A Vietnamese-linked operation dubbed AccountDumpling is using Google AppSheet as a phishing relay to steal Facebook credentials, enabling account takeover at scale...
AccountDumpling Google AppSheet Facebook phishing campaign
CampaignAbout this happening: A Vietnamese-linked operation dubbed AccountDumpling is using Google AppSheet as a phishing relay to steal Facebook credentials, enabling account takeover at scale...
Jinkusu's Starkiller phishing-as-a-service ecosystem commoditizes account takeover
Threat Actor Meta
H score37
First: 20.02.2026 22:00
Last: 20.02.2026 22:00
Sources 1
About this happening:
A new phishing-as-a-service operation tied to Jinkusu is proxying real login pages through attacker infrastructure, making MFA bypass and account takeover easier for low-s...
Jinkusu's Starkiller phishing-as-a-service ecosystem commoditizes account takeover
Threat Actor MetaAbout this happening: A new phishing-as-a-service operation tied to Jinkusu is proxying real login pages through attacker infrastructure, making MFA bypass and account takeover easier for low-s...
Starkiller dark-web phishing platform scales credential theft as a SaaS-style criminal service
Threat Actor Meta
H score36
First: 19.02.2026 14:00
Last: 19.02.2026 14:00
Sources 1
About this happening:
The Starkiller phishing platform has emerged as a SaaS-style criminal service, raising the scale and durability of credential theft operations. It is sold on the dark we...
Starkiller dark-web phishing platform scales credential theft as a SaaS-style criminal service
Threat Actor MetaAbout this happening: The Starkiller phishing platform has emerged as a SaaS-style criminal service, raising the scale and durability of credential theft operations. It is sold on the dark we...
Timeline
-
25.08.2026 16:00 2 articles · 1h ago
RecruitTrap domains impersonate major employers and filter for corporate email addresses
Technical Analysis UpdateZimperium’s zLabs identified 46 previously unpublished IOCs tied to RecruitTrap recruitment-themed domains that impersonated major companies, including Amazon, Apple, Boeing, Deloitte, Emirates Group, Heineken, Lego and Louis Vuitton. The phishing flow rejected personal email domains and required corporate credentials, showing a design focused on enterprise accounts and access to internal communications and cloud applications.
Show sources
- Fake Recruiter Scams Target Corporate Credentials on Mobile — www.infosecurity-magazine.com — 25.08.2026 16:00
- Fake Recruiter Scams Target Corporate Credentials on Mobile — www.infosecurity-magazine.com — 25.08.2026 16:00
-
25.08.2026 16:00 1 articles · 1h ago
Zimperium reports fake recruiter scams targeting mobile corporate credentials
Initial DisclosureZimperium’s zLabs reported fake recruiter scams that targeted corporate credentials on mobile devices using full-screen counterfeit login pages and pre-qualification checks that rejected personal email addresses. The reporting connected the activity to RecruitTrap and highlighted the risk that stolen corporate access could expose OAuth tokens, internal communications and cloud applications.
Show sources
- Fake Recruiter Scams Target Corporate Credentials on Mobile — www.infosecurity-magazine.com — 25.08.2026 16:00