Zimperium

Extended Rapid Response: Zimperium Identifies RecruitTrap Recruit Scams are Targeting Enterprise Credentials on Mobile

Written by Esteban Tissot | Aug 24, 2026

The recent research on The Growing Threat of Browser-in-the-Browser (BitB) Recruitment Scams highlights an escalating trend in social engineering: threat actors impersonate real HR personnel across multiple well-known companies to execute highly convincing, interview-themed phishing attacks. By scraping public profile data, attackers craft hyper-realistic scheduling flows designed to bypass traditional user skepticism.

While desktop users encounter a simulated popup browser window (BitB), mobile devices present a unique vulnerability. On smaller screens, the attack automatically adapts, replacing the BitB frame with a full-screen counterfeit login page. Without traditional desktop browser chrome or visible URL bars, mobile victims have virtually no visual indicators to distinguish a fake login from a legitimate OAuth prompt.

A critical finding in this campaign is the attacker's strict pre-qualification logic. The phishing kit does not process every victim; it actively screens inputs and rejects personal email domains. By enforcing the use of corporate credentials, threat actors specifically target high-value enterprise access. Once inside a single corporate account, attackers gain immediate access to OAuth tokens, internal communications, and cloud applications, enabling rapid lateral movement across the organization.

While recent industry reports highlight a spike in fake recruitment and scheduling portals over the last two months targeting corporate credentials, Zimperium telemetry reveals a much broader, long-standing threat pattern. Our 1-year telemetry analysis shows that brand-impersonating recruitment domains (utilizing conventions like [company]-global.com or [company]-careers.com) rely on a persistent hosting distribution. As shown in Figure 1, rather than constantly shifting to obscure networks, the underlying infrastructure shows a sustained reliance on specific cloud, hosting, and parking providers—led by Amazon.com and SEDO GmbH at the ASN level, alongside recurring active subnet blocks such as 91.195.240.0/22 and 13.52.128.0/18. During our analysis, we identified 46 previously unpublished IOCs that we could associate with the aforementioned research.

Figure 1: Top 10 CIDR & ASN Distribution

This persistent infrastructure frequently leverages high-profile global brands across diverse sectors. In our sample, the most notably targeted entities span e-commerce, luxury goods, big tech, aviation, and retail, such as: Amazon, Louis Vuitton, Apple, FIFA, Emirates Group, Boeing, Heineken, Deloitte, Central Network Retail Group (CNRG), and Lego among others.

Because static URL blocklists struggle to keep up with newly registered lookalike domains on these shared networks, traditional feeds leave a critical window of exposure. As detailed in Table 2 below, global threat feeds often take days—and in many cases, months or years—to publicly flag these impersonation domains after their initial registration.

 

Domains

Domain Registration

Date

Public Feeds

Reported Date

Time Difference

in Days

hbc-careers[.]com

10/8/2019

1/22/2026

2297

insulet-careers[.]com

11/29/2021

12/3/2025

1464

xmtrading-global[.]com

2/4/2025

7/14/2026

525

andmore-global[.]com

3/6/2025

12/16/2025

284

mondial-relay-global[.]com

6/27/2025

8/26/2025

59

expedia-careers[.]com

6/27/2026

8/17/2026

50

fifahr-careers[.]com

6/24/2026

7/6/2026

12

aa-careers[.]com

6/25/2026

7/7/2026

11

levis-careers[.]com

6/27/2026

7/7/2026

9

mckinsey-careers[.]com

6/29/2026

7/7/2026

7

Table 2: Top 10 0-Days

 

By dynamically inspecting network traffic, Zimperium Mobile Threat Defense (MTD) protects all enterprise employees across their devices—blocking credential harvesting in real time, even when the attack adapts to mobile screens as a full-screen login spoof. Ultimately, defending against these targeted campaigns requires looking beyond desktop-centric web gateways and securing corporate identities at the mobile touchpoint.