RecruitTrap Uses Job Lures for Account Takeover

CTM360 says the RecruitTrap campaign used more than 3,000 recruitment phishing URLs over two months to steal Google and Facebook credentials through fake interview pages. The campaign impersonated recruiters, and marketing staff were the main target. The lure opens a browser-in-the-browser login window that looks like a real Google or Facebook sign-in, complete with a spoofed address bar and padlock. In the more advanced flow, the attackers relay the multi-factor authentication prompt in real time, so the victim appears to log in normally while handing over a usable session. For teams that use Google or Facebook to run ads or manage brand accounts, the exposure sits well beyond the inbox. A successful hit can hand an attacker control of ad platforms, social pages, customer records, and other business services tied to that identity.

Part of the PlainSec briefing for 2026-08-17

Editions

Sources