The recent research on The Growing Threat of Browser-in-the-Browser (BitB) Recruitment Scams highlights an escalating trend in social engineering: threat actors impersonate real HR personnel across multiple well-known companies to execute highly convincing, interview-themed phishing attacks. By scraping public profile data, attackers craft hyper-realistic scheduling flows designed to bypass traditional user skepticism.
While desktop users encounter a simulated popup browser window (BitB), mobile devices present a unique vulnerability. On smaller screens, the attack automatically adapts, replacing the BitB frame with a full-screen counterfeit login page. Without traditional desktop browser chrome or visible URL bars, mobile victims have virtually no visual indicators to distinguish a fake login from a legitimate OAuth prompt.
A critical finding in this campaign is the attacker's strict pre-qualification logic. The phishing kit does not process every victim; it actively screens inputs and rejects personal email domains. By enforcing the use of corporate credentials, threat actors specifically target high-value enterprise access. Once inside a single corporate account, attackers gain immediate access to OAuth tokens, internal communications, and cloud applications, enabling rapid lateral movement across the organization.
While recent industry reports highlight a spike in fake recruitment and scheduling portals over the last two months targeting corporate credentials, Zimperium telemetry reveals a much broader, long-standing threat pattern. Our 1-year telemetry analysis shows that brand-impersonating recruitment domains (utilizing conventions like [company]-global.com or [company]-careers.com) rely on a persistent hosting distribution. As shown in Figure 1, rather than constantly shifting to obscure networks, the underlying infrastructure shows a sustained reliance on specific cloud, hosting, and parking providers—led by Amazon.com and SEDO GmbH at the ASN level, alongside recurring active subnet blocks such as 91.195.240.0/22 and 13.52.128.0/18. During our analysis, we identified 46 previously unpublished IOCs that we could associate with the aforementioned research.
|
|
|
|
Figure 1: Top 10 CIDR & ASN Distribution |
|
This persistent infrastructure frequently leverages high-profile global brands across diverse sectors. In our sample, the most notably targeted entities span e-commerce, luxury goods, big tech, aviation, and retail, such as: Amazon, Louis Vuitton, Apple, FIFA, Emirates Group, Boeing, Heineken, Deloitte, Central Network Retail Group (CNRG), and Lego among others.
Because static URL blocklists struggle to keep up with newly registered lookalike domains on these shared networks, traditional feeds leave a critical window of exposure. As detailed in Table 2 below, global threat feeds often take days—and in many cases, months or years—to publicly flag these impersonation domains after their initial registration.
|
Domains |
Domain Registration Date |
Public Feeds Reported Date |
Time Difference in Days |
|
hbc-careers[.]com |
10/8/2019 |
1/22/2026 |
2297 |
|
insulet-careers[.]com |
11/29/2021 |
12/3/2025 |
1464 |
|
xmtrading-global[.]com |
2/4/2025 |
7/14/2026 |
525 |
|
andmore-global[.]com |
3/6/2025 |
12/16/2025 |
284 |
|
mondial-relay-global[.]com |
6/27/2025 |
8/26/2025 |
59 |
|
expedia-careers[.]com |
6/27/2026 |
8/17/2026 |
50 |
|
fifahr-careers[.]com |
6/24/2026 |
7/6/2026 |
12 |
|
aa-careers[.]com |
6/25/2026 |
7/7/2026 |
11 |
|
levis-careers[.]com |
6/27/2026 |
7/7/2026 |
9 |
|
mckinsey-careers[.]com |
6/29/2026 |
7/7/2026 |
7 |
|
Table 2: Top 10 0-Days |
|||
By dynamically inspecting network traffic, Zimperium Mobile Threat Defense (MTD) protects all enterprise employees across their devices—blocking credential harvesting in real time, even when the attack adapts to mobile screens as a full-screen login spoof. Ultimately, defending against these targeted campaigns requires looking beyond desktop-centric web gateways and securing corporate identities at the mobile touchpoint.