Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

CTM360 Uncovers a Global Recruitment Phishing Campaign Using Browser-in-the-Browser (BitB) Credential Traps




A global recruitment-themed phishing campaign using Browser-in-the-Browser (BitB) credential traps has been uncovered by CTM360, with over 3,000 phishing URLs identified. The campaign targets marketing professionals and uses fake interview invitations to steal sensitive credentials. Learn how to identify and respond to this attack and stay protected from phishing and credential traps.

  • A large-scale, global phishing campaign has been uncovered, targeting marketing professionals and using sophisticated Browser-in-the-Browser (BitB) credential traps to steal Google and Facebook credentials.
  • The campaign has identified over 3,000 phishing URLs across 14 sectors, with a majority of targets being marketing professionals.
  • The campaign's modus operandi involves sending unsolicited interview invitations to job seekers, leading to fake authentication popups and attempts to steal credentials or MFA prompts.
  • The attackers use Browser-in-the-Browser (BitB) techniques to establish trust and filter out personal email domains, focusing on valuable enterprise identities.
  • The phishing pages primarily used a Calendly theme, with 96% of the URLs utilizing this theme, and used Cloudflare to hide the attackers' real servers.
  • The campaign is designed for rapid rebranding, making it difficult for victims to distinguish between legitimate and malicious emails.
  • To identify and respond to this attack, users should verify unsolicited interview invitations through an independently sourced channel and navigate to the organization's official careers site.
  • Organizations can reduce exposure by using phishing-resistant authentication, monitoring for lookalike recruitment domains, and correlating suspicious emails with unusual sign-in attempts.



  • A recent report by CTM360, a trusted cybersecurity news platform, has uncovered a large-scale, global recruitment-themed phishing campaign that utilizes sophisticated Browser-in-the-Browser (BitB) credential traps to steal sensitive Google and Facebook credentials. The campaign, which is believed to have been launched in recent months, has already identified over 3,000 phishing URLs across 14 sectors, with a majority of targets being marketing professionals. The campaign's focus on marketing roles appears deliberate, as compromised marketing accounts can provide access to advertising platforms, corporate social media profiles, customer data, email, and other business-critical services.

    The campaign's modus operandi involves sending unsolicited interview invitations to job seekers, which direct them to either a counterfeit Calendly-style scheduling page or a brand-specific recruitment portal. Both flows lead to a fake authentication popup with a spoofed address bar and padlock, which utilizes a Browser-in-the-Browser (BitB) technique to display a fake window that cannot be moved outside the current browser tab. The attackers use this technique to establish trust with the victim, before attempting to steal their credentials or MFA prompts in real-time.

    CTM360's technical analysis of one Calendly-style phishing URL revealed that the page behaved as a state machine, moving the victim through staged scenes for CAPTCHA, username, password, and multiple two-factor authentication methods. The page filtered out personal email domains and only advanced corporate accounts, focusing on valuable enterprise identities. The attackers also used CAPTCHA and browser-reload checks to filter traffic before collecting credentials.

    The phishing pages identified by CTM360 primarily used a Calendly theme, with 96% of the URLs utilizing this theme. Many of the pages used Cloudflare to hide the attackers' real servers, with 93.1% of the URLs using dedicated or registered hosts. The most common top-level domain used was .cfd, followed by .com, .info, .works, and .work.

    The campaign is also designed for rapid rebranding, with the same template being able to be adapted by changing the employer name, recruiter identity, background, slogan, and authentication provider. This allows the attackers to quickly switch between different brands and organizations, making it difficult for victims to distinguish between legitimate and malicious emails.

    To identify and respond to this attack, users should verify unsolicited interview invitations through an independently sourced company channel and navigate to the organization's official careers site instead of using links in the message. A genuine Google sign-in should run on accounts.google.com, or another verified Google origin. In a BitB attack, the visible address bar and padlock are part of the web page, the fake window cannot be moved outside the current browser tab, and browser controls or privacy links may be decorative.

    Organizations can reduce exposure by using phishing-resistant authentication such as passkeys or hardware-backed WebAuthn, monitoring for lookalike recruitment domains, and correlating suspicious recruitment emails with unusual sign-in attempts or new sessions. Anyone who entered credentials or an MFA code into a suspected recruitment page should immediately change the affected password, revoke active sessions and tokens, review sign-in activity, mailbox rules, and OAuth grants, and notify their security team.

    The report highlights the importance of being aware of these types of attacks and taking proactive measures to protect oneself and one's organization. As the use of AI and automation continues to grow, it is essential to stay vigilant and adapt to new threats and tactics, such as the use of Browser-in-the-Browser (BitB) credential traps.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/CTM360-Uncovers-a-Global-Recruitment-Phishing-Campaign-Using-Browser-in-the-Browser-BitB-Credential-Traps-ehn.shtml

  • https://thehackernews.com/2026/08/ctm360-uncovers-over-3000-recruitment.html


  • Published: Mon Aug 17 08:46:27 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us