negativeSYS.SOURCE: The Hacker News• 2026-08-14T16:27:00+05:30
CTM360 Discovers 3,000 Recruitment Phishing URLs Leveraging Browser-in-the-Browser Credential Theft Techniques
CTM360 discovered over 3,000 recruitment phishing URLs using Browser-in-the-Browser (BitB) techniques to steal credentials and relay MFA prompts. The campaign targeted marketing roles through sophisticated state-machine phishing pages mimicking Calendly and brand-specific portals.
Cybersecurity researchers have uncovered a large-scale, global recruitment-themed phishing campaign that uses fake interview scheduling pages and Browser-in-the-Browser (BitB) windows to steal Google and Facebook credentials and, in more advanced cases, relay multi-factor authentication (MFA) prompts in real time.
CTM360, which detailed the activity in a new report titled RecruitTrap, said it
*** END OF TRANSMISSION ***