What happened
Security firm CTM360 published research on a large phishing operation it calls RecruitTrap, documenting more than 3,000 phishing URLs collected over two months. The campaign impersonates recruiters and hiring processes from over 50 real organizations across 14 sectors. Victims are steered to a fake interview-scheduling page, most of them styled to look like Calendly, then prompted to sign in with Google or Facebook. That login window is the trap: it is a browser-in-the-browser popup, a fake window drawn inside the web page with a spoofed address bar and padlock. In the more advanced cases, the kit relays multi-factor authentication prompts in real time, so even a one-time code can be captured. Notably, the researchers found marketing professionals made up the majority of targets, and about half of the branded phishing portals were hosted on AWS EC2 addresses.
Why it matters for your business
The targeting choice is the tell. A marketing employee's Google or Facebook login often unlocks your ad accounts, business pages, customer lists, and email. For a small business, a hijacked ad account can mean fraudulent spend on your card and a locked-out Facebook page that took years to build. And because job hunting happens on personal time, an employee can hand over a work-connected credential without your systems ever seeing the phishing page.
What to do about it
A few practical defenses hold up well against this technique:
- Tell staff a real login window can be dragged outside the browser; a browser-in-the-browser popup cannot leave the page.
- Move Google and Facebook business accounts to passkeys or hardware-key MFA, which cannot be relayed the way a texted code can.
- Treat unsolicited recruiter outreach that requires a login to schedule an interview as a red flag, and verify the recruiter through the company's own website.
