Research on Browser-in-the-Browser recruitment scams shows threat actors impersonating real HR staff from major companies to run highly convincing interview-themed phishing campaigns. The attacks adapt to mobile by swapping the fake browser popup for a full-screen login page, while infrastructure and lookalike domains tied to brands like Amazon, Apple, and FIFA remain active for long periods. #BrowserintheBrowser #Amazon #Apple #FIFA #Zimperium
Keypoints
- Threat actors impersonate HR personnel from well-known companies to lure victims into recruitment-themed phishing attacks.
- Attackers scrape public profile data to build realistic scheduling and interview flows that reduce suspicion.
- On desktop, the scam uses a simulated browser popup; on mobile, it shifts to a full-screen counterfeit login page without obvious URL cues.
- The phishing kit enforces corporate-only email input, filtering out personal domains to focus on high-value enterprise accounts.
- Compromised corporate accounts can expose OAuth tokens, internal communications, and cloud applications, enabling rapid lateral movement.
- Telemetry shows a long-lived infrastructure model using shared cloud, hosting, and parking providers rather than rapidly changing networks.
- Zimperium identified 46 previously unpublished IOCs and observed delayed public detection of many impersonation domains.
MITRE Techniques
- [T1589 ] Gather Victim Identity Information – Attackers scrape public profile data to make recruitment lures credible (‘By scraping public profile data, attackers craft hyper-realistic scheduling flows’).
- [T1566.002 ] Spearphishing Link – Victims are drawn into interview-themed phishing pages through fake recruitment and scheduling portals (‘interview-themed phishing attacks’ and ‘fake recruitment and scheduling portals’).
- [T1036 ] Masquerading – The phishing pages impersonate legitimate HR and login experiences, including a BitB popup and counterfeit OAuth-style prompt (‘simulate popup browser window’ and ‘full-screen counterfeit login page’).
- [T1133 ] External Remote Services – Stolen corporate credentials are used to access enterprise accounts and services (‘target high-value enterprise access’ and ‘access to OAuth tokens, internal communications, and cloud applications’).
- [T1528 ] Steal Application Access Token – Compromised accounts provide OAuth tokens that can be reused for access (‘gain immediate access to OAuth tokens’).
- [T1190 ] Exploit Public-Facing Application – Public recruitment and scheduling portals are abused as the entry point into the campaign (‘fake recruitment and scheduling portals’).
Indicators of Compromise
- [Domains ] Lookalike recruitment and careers sites used for impersonation – hbc-careers[.]com, insulet-careers[.]com, and 8 more domains
- [Network Blocks ] Recurring active subnet blocks supporting the infrastructure – 91.195.240.0/22, 13.52.128.0/18
- [Organizations / Brands ] Impersonated entities appearing in the lure infrastructure – Amazon, Louis Vuitton, Apple, FIFA, Emirates Group, Boeing, Heineken, Deloitte, CNRG, and Lego
- [Hosting / Providers ] Persistent infrastructure associated with hosting and parking services – Amazon.com, SEDO GmbH
- [Asn / Infra Distribution ] Top-level infrastructure distribution references – ASN-level reliance on Amazon.com and SEDO GmbH, with recurring subnet activity across shared hosting