Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-15 ยท updated: 2026-08-15 ยท tags: [incident, phishing, browser-in-the-browser, credential-theft, recruitment, mfa-relay, sector-global-macro] ยท confidence: medium ยท affected_sectors: [global-macro] ยท au_impact: false

CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser

  • Source: The Hacker News
  • Date: 2026-08-14
  • Reliability: Tier 2/4 โ€” Established cyber journalism
  • Entity: CTM360 (RecruitTrap campaign)

Summary

CTM360's RecruitTrap research uncovered 3,000+ recruitment-themed phishing URLs weaponised with Browser-in-the-Browser (BitB) attacks. Fake job-interview pages steal Google and Facebook credentials and relay mobile MFA codes. The campaign targeted 50+ organisations across 14 sectors, with marketing professionals the most targeted group.

Key Facts

  • More than 3,000 malicious recruitment phishing URLs identified
  • BitB technique spoofs legitimate browser windows for credential theft
  • Fake interview pages harvest Google/Facebook credentials and relay MFA
  • 50+ organisations across 14 sectors impacted; marketing professionals most targeted

Sector

Global (Macro) โ€” Recruitment-driven social engineering spans multiple sectors.

Source

https://thehackernews.com/2026/08/ctm360-uncovers-over-3000-recruitment.html

Reliability

Tier 2 โ€” Established cyber journalism; probable/evidenced campaign findings.

Date

2026-08-14

Related Pages

Sources: raw/digests/Cyber-Digest-2026-08-15