Bogus Recruiters Harvest Corporate Passwords via Mobile Phishing Campaign
What Happened — Scammers posing as HR recruiters are running interview‑scheduling scams that end with a fake mobile login page. Using the “browser‑in‑the‑browser” (BitB) technique, the kit displays a full‑screen credential prompt that looks indistinguishable from a legitimate corporate sign‑in, capturing high‑value corporate passwords and associated OAuth tokens.
Why It Matters for Compliance & Audit Readiness
- The attack targets the exact access‑control weaknesses SOC 2 CC6.1 (Logical Access) is designed to mitigate – lack of MFA, insufficient credential‑use monitoring, and missing mobile‑specific controls.
- Continuous evidence of security‑awareness training and phishing‑simulation results is now a critical audit artifact to demonstrate due diligence.
- Mobile‑focused web‑gateway logs and OAuth‑token activity feeds provide the real‑time evidence SOC 2 auditors expect for “monitoring of security events.”
Who Is Affected – Enterprises across e‑commerce, luxury goods, aviation, retail, professional services, and any organization that relies on corporate credentials for cloud applications.
Recommended Actions –
- Enforce MFA and conditional‑access policies for all corporate accounts, especially on mobile devices.
- Extend phishing‑simulation and security‑awareness programs to cover mobile‑only scenarios and the BitB technique.
- Deploy mobile‑aware web gateways or secure browsers that expose address‑bar cues and block look‑alike domains.
- Implement continuous monitoring of OAuth‑token issuance and anomalous credential use; retain logs as audit evidence.
Source: Help Net Security
Technical Notes – The BitB kit switches from a full browser window on desktop to a full‑screen overlay on mobile, eliminating visual cues like the address bar. Attackers pre‑qualify victims by discarding personal email addresses and only presenting the credential prompt to corporate accounts. Domains are hosted primarily on AWS and SEDO GmbH, with 46 new IOCs disclosed by Zimperium.