CTM360 identified more than 3,000 phishing URLs over two months tied to a single recruitment-themed campaign that used counterfeit interview pages and a Browser-in-the-Browser (BitB) technique to harvest Google and Facebook credentials and, in some cases, relay multi-factor authentication prompts in real time.
How the Browser-in-the-Browser (BitB) trap works
The campaign relied on a BitB trick that displays a fake authentication popup complete with a spoofed address bar and padlock. CTM360 reported that on desktop the counterfeit window appears inside the page, and on mobile it can surface as a full‑screen counterfeit login. In the attack flow, victims are asked to click “Continue with Google/Facebook”; the BitB element then mimics an authentic sign‑in dialog while remaining a part of the web page. CTM360 noted telltale signs of BitB: the fake address bar and padlock are part of the page, the fake window cannot be moved outside the current browser tab, and browser controls or privacy links may be decorative.
Calendly-style and brand‑specific recruitment portals
CTM360 observed two primary lures. One was a counterfeit Calendly‑style scheduling page that copied employer branding and sometimes reused names, photographs and job titles of real recruiters. The other was a brand‑specific recruitment portal that asked targets to pick an interview time and supply basic contact details. Both flows culminated in the same “Continue with Google/Facebook” BitB login trap.
Behind the user experience, at least one Calendly‑style URL CTM360 analyzed operated as a live state machine rather than a static form. A Svelte/SvelteKit front end moved victims through staged scenes for CAPTCHA, username, password and multiple two‑factor methods — including one‑time passcodes (OTP), phone number matching and suffix verification. The site stored a browser‑specific session identifier in sessionStorage and maintained a persistent Socket.IO channel so the backend could control which screen appeared next. CAPTCHA and browser‑reload checks filtered traffic before credentials were requested; the pages also filtered out personal email domains and advanced only corporate accounts.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleShared infrastructure, rapid rebranding, and scale
CTM360 documented more than 3,000 URLs across a shared template and infrastructure set up for rapid rebranding: employers’ names, recruiter identities, background art and the authentication provider could be swapped while preserving the same 30‑minute meeting and login flow. About 96% of observed phishing pages used a Calendly theme. Many pages used Cloudflare in front of the attackers’ servers.
The counterfeit brand recruitment portal used 116 unique observed hosts. Of these, 93.1% used dedicated or registered hosts and 50.9% resolved to AWS EC2 IP addresses and ranges, indicating repeated hostnames and reused infrastructure. CTM360 deduplicated 813 registered domains: the most common top‑level domain was .cfd at 40%, followed by .com (25.1%), .info (15.1%), .works (10.5%) and .work (6.3%).
Targets: marketing roles, 50+ organizations, 14 sectors
The campaign impersonated recruiters and recruitment processes tied to more than 50 organizations spanning 14 sectors. CTM360 recorded that marketing professionals accounted for the majority of observed targets. The report explains the likely rationale: compromised marketing accounts can provide access to advertising platforms, corporate social media profiles, customer data, email and other business‑critical services. The brands used in the campaign were concentrated in recruitment, technology, luxury goods and travel, which together made up about 58% of the brands CTM360 observed.
How to detect, respond, and what different groups should do
CTM360 offered concrete user and organizational responses grounded in the campaign’s mechanics. Users are advised to verify unsolicited interview invitations through an independently sourced company channel and to navigate to the organization’s official careers site instead of following links in the message. A genuine Google sign‑in should run on accounts.google.com or another verified Google origin; a password manager failing to recognize or autofill an expected origin is a warning sign.
For defenders, CTM360 recommended reducing exposure with phishing‑resistant authentication such as passkeys or hardware‑backed WebAuthn, monitoring for lookalike recruitment domains, and correlating suspicious recruitment emails with unusual sign‑in attempts or new sessions. CTM360 also spelled out incident steps for compromised users: immediately change the affected password, revoke active sessions and tokens, review sign‑in activity, mailbox rules and OAuth grants, and notify the security team.
RecruitTrap, CTM360’s report, shows how a familiar hiring interaction — a scheduling page and an apparent sign‑in popup — can be converted into a live, scalable identity attack that harvests credentials and relays MFA. The combination of a convincing BitB window and a live backend state machine is what turns a single fake interview into an account takeover if defensive signals are missed.
Read the original report at: https://thehackernews.com/2026/08/ctm360-uncovers-over-3000-recruitment.html




