VMTech
Discuss a project

CTM360 maps recruitment phishing campaign using BitB login traps

CTM360 maps recruitment phishing campaign using BitB login traps

CTM360 has identified more than 3,000 recruitment-themed phishing URLs over two months in a campaign it calls RecruitTrap. The operation impersonated recruiters and hiring processes linked to more than 50 organisations in 14 sectors, using fake interview scheduling pages and Browser-in-the-Browser (BitB) windows to capture Google and Facebook credentials.

Marketing professionals made up the largest share of observed targets. CTM360 said the choice appears deliberate: a compromised marketing account can expose advertising platforms, corporate social profiles, customer data, email and other business-critical services.

Two recruitment lures, one credential trap

The campaign begins with an unsolicited email or meeting invitation apparently sent by a recruiter from a recognisable company. Messages refer to a recipient’s professional background and invite them to arrange an interview or informal conversation.

Victims are directed either to a counterfeit Calendly-style scheduler or a recruitment portal tailored to a specific brand. The pages can reuse publicly available names, photographs and job titles belonging to real recruiters. After a visitor chooses a time or supplies basic contact details, both flows present a Continue with Google or Facebook option.

That action opens a fake authentication prompt using BitB. The false window includes a spoofed address bar and padlock, while mobile users may instead see a full-screen counterfeit sign-in page. A genuine Google sign-in runs on accounts.google.com or another verified Google origin; the apparent browser chrome in a BitB page is part of the page itself.

Live MFA relay and shared infrastructure

CTM360’s analysis of one Calendly-style URL found a Svelte/SvelteKit front end that behaved as a state machine, not a static credential form. It moved victims through CAPTCHA, username, password and several two-factor authentication stages, including OTP, phone-number matching and suffix verification.

A browser-specific identifier was held in sessionStorage and a persistent Socket.IO channel let the backend decide which screen to show next. CAPTCHA and reload checks filtered traffic, while personal email domains were excluded so that the campaign advanced corporate accounts. After credentials were entered, attackers could sign in to the genuine service and relay the resulting MFA request to the victim.

If the sign-in succeeded, the operator obtained an authenticated session and could redirect the victim to a legitimate Calendly page to reduce suspicion. The mechanism reflects the phishing and MFA-bypass risks described in phishing and MFA-bypass risks, while applying them to a familiar recruitment workflow.

About 96% of the URLs used a Calendly theme. CTM360 found 116 unique observed hosts for the brand-specific portal, with 93.1% using dedicated or registered hosts and 50.9% hosted on AWS EC2 IP addresses and ranges. Among 813 deduplicated registered domains, .cfd accounted for 40%, followed by .com at 25.1%, .info at 15.1%, .works at 10.5% and .work at 6.3%.

What security teams should do

Organisations should monitor lookalike recruitment domains and correlate suspicious hiring messages with unusual sign-ins or new sessions. Employees should independently verify unsolicited interview invitations through a company channel and visit official careers sites rather than following links in a message.

Password-manager failures to recognise or fill the expected origin can be a warning sign, as can a login window that cannot move beyond the current browser tab. Businesses can limit exposure with phishing-resistant authentication, including passkeys or hardware-backed WebAuthn. Anyone who submitted credentials or an MFA code should change the affected password, revoke active sessions and tokens, review sign-in activity, mailbox rules and OAuth grants, and notify the security team.

#cybersecurity#phishing#identitysecurity#webauthn
Open analytics
On the site 0 views
min read 4 17.08.2026
Instagram

CTM360 maps recruitment phishing campaign using BitB login traps

Open the post on Instagram ↗