Recruitment‑Themed Phishing Campaign Uses Browser‑in‑the‑Browser Traps to Harvest Google and Facebook Credentials
What Happened — Researchers at CTM360 identified a global phishing operation that masquerades as interview‑scheduling pages. The attackers embed Browser‑in‑the‑Browser (BitB) windows that capture Google and Facebook login credentials and, in advanced variants, relay MFA prompts in real time. Over 3,000 unique phishing URLs were catalogued in the “RecruitTrap” report.
Why It Matters for Compliance & Audit Readiness
- Phishing attacks that harvest credentials directly test the effectiveness of SOC 2 CC6.1 (Logical Access) and CC6.2 (Multi‑Factor Authentication) controls; a lapse can become a finding in an audit.
- Continuous evidence of employee awareness training and phishing‑simulation results is essential to demonstrate due diligence and a defensible audit trail.
- Verisq’s Security Awareness capability provides automated training delivery, phishing‑simulation metrics, and audit‑ready evidence of policy enforcement.
Who Is Affected
- Professional services firms (recruiters, staffing agencies)
- Any organization with employees who receive recruitment outreach or schedule interviews online
- Users of Google Workspace and Facebook Business accounts
Recommended Actions
- Map the phishing scenario to SOC 2 access‑control criteria (CC6.1, CC6.2) and verify that training records and MFA enforcement are up‑to‑date.
- Deploy simulated phishing campaigns that mimic recruitment lures and capture click‑through rates.
- Enforce strict MFA policies and monitor for anomalous authentication attempts on corporate IdP logs.
Source: The Hacker News
Technical Notes
- Attack vector: Phishing emails → fake interview scheduling pages → Browser‑in‑the‑Browser (BitB) credential capture.
- No CVE; the technique exploits user trust and UI deception rather than a software flaw.
- Stolen data: Google and Facebook usernames/passwords; MFA tokens relayed in real time.
Source: CTM360 “RecruitTrap” report