Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices

August 26, 2026

Four in Five AI Tools Run with No IT Oversight, Research Finds

August 26, 2026

Tortoiseshell Expands Toolset With New Backdoor, SSH Tunnel

August 26, 2026
Facebook X (Twitter) Instagram
Wednesday, August 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Fake Recruiter Scams Target Corporate Credentials on Mobile
News

Fake Recruiter Scams Target Corporate Credentials on Mobile

Team-CWDBy Team-CWDAugust 25, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Fake recruiter scams have been targeting corporate credentials on mobile devices, using full-screen login pages and pre-qualification checks to reject personal email addresses and focus on enterprise accounts.

Researchers at Zimperium’s zLabs analyzed the activity and identified 46 previously unpublished indicators of compromise (IOCs) linked to recruitment-themed domains impersonating major companies.

The August 24 research found that the campaigns had persisted across a range of cloud, hosting and domain-parking providers.

Recruitment Pages Screen For Corporate Targets

The campaign, tracked by Zimperium in connection with RecruitTrap activity, impersonated employers and recruiters through domains using names associated with careers and global recruitment. The researchers found examples impersonating brands including Amazon, Apple, Boeing, Deloitte, Emirates Group, Heineken, Lego and Louis Vuitton, among others.

On desktop devices, victims may encounter a simulated browser-in-the-browser (BitB) login. On mobile devices, the phishing flow instead presents a full-screen counterfeit login page, removing browser elements such as the address bar that could help users identify the deception.

The phishing kit also screened submitted information. Zimperium found that it rejected personal email domains and required corporate credentials, indicating that the campaign was designed to prioritize accounts that could provide access to enterprise resources.

An attacker gaining access to a corporate account could obtain OAuth tokens and reach internal communications and cloud applications, according to Zimperium. The researchers said this could support further movement through an organization.

Read more on mobile phishing: Mobile Phishing Attacks Surge with 16% of Incidents in US

Infrastructure Persists Across Hosting Providers

Zimperium’s one-year telemetry analysis found that the recruitment domains frequently remained on recurring cloud, hosting and parking infrastructure rather than continuously moving between obscure networks.

Amazon and SEDO were among the most frequently observed providers at the autonomous system number (ASN) level.

Zimperium said the persistence of lookalike recruitment domains can leave gaps in conventional URL blocklists, as newly registered sites may remain operational before they are added to public threat feeds.

To defend against this and similar threats, the company recommended securing corporate identities at the mobile touchpoint and dynamically inspecting network traffic to detect credential-harvesting attempts, rather than relying solely on desktop-focused web gateways and static URL blocklists.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleClop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
Next Article Australia Warns of Active Exploitation of Critical TeamCity Server Fla
Team-CWD
  • Website

Related Posts

News

Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices

August 26, 2026
News

Tortoiseshell Expands Toolset With New Backdoor, SSH Tunnel

August 26, 2026
News

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

August 26, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

All Major LLMs Exposed to Multi-Turn Manipulation, Warn Researchers

May 27, 20269 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Why the tech industry needs to stand firm on preserving end-to-end encryption

September 12, 2025

What are brushing scams and how do I stay safe?

December 24, 2025

Why children’s data is a long-term identity risk

June 3, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.