Published · 6d agoSecurity2 min read
3,000 Fake Recruiter URLs: The Number Under The $7M Expired-Domain Claim
CTM360 counted more than 3,000 phishing URLs impersonating hiring processes at over 50 organisations in two months. The dollar figure attached to that campaign is not in the material we hold.
Not a builder's beat, but builders have a standing stake in it.See today for builders
What happened
- Over two months, CTM360 identified more than 3,000 phishing URLs impersonating recruiters and hiring processes from over 50 organizations.
- The RecruitTrap campaign uses fake interview invitations, counterfeit scheduling portals, and Browser-in-the-Browser (BitB) login windows to steal corporate credentials and relay MFA challenges.
- The campaign primarily targets marketing professionals and filters for corporate email accounts, enabling credential theft and potential account takeover.
- A BitB phishing page uses JavaScript to create a simulated browser window that displays a URL of the attacker's choice, such as https://accounts.google.com or https://login.microsoftonline.com.
- In a BitB attack the simulated address bar shows the URL only as an image or text, and the full-screen display mode blocks the real site's URL, so the user may not notice the absence of SSL certificates or other security indicators.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Over two months, CTM360 says it identified more than 3,000 phishing URLs impersonating recruiters and hiring processes at more than 50 organisations [1]. That count is the figure this desk can stand behind. The $7M expired-domain spend is not present anywhere in the material supplied to us, so it stays unsourced until someone shows the receipts [11].
What the grounded number turns on is breadth, not cleverness. More than 3,000 URLs across more than 50 impersonated organisations works out to roughly 60 distinct URLs per brand [10]. The spend, whatever it is, goes on inventory: names and hosting that arrive already looking legitimate, because the campaign's whole pitch is borrowed credibility. Victims get a fake interview invitation, then a counterfeit scheduling portal, then a Browser-in-the-Browser login window that captures corporate credentials and relays MFA challenges [2]. The targeting is deliberate: mainly marketing professionals, with filtering for corporate email accounts, which is what makes account takeover worth the effort [3].
The trust signals are not bypassed, they are drawn. According to CTM360, a BitB page uses JavaScript to simulate a browser window and print a URL of the attacker's choosing in it, such as https://login.microsoftonline.com [4]. The address bar is only an image or text, and full-screen mode hides the real URL, so the missing certificate indicators go unnoticed [5]. Submitted credentials leave by AJAX or a concealed form, and the attacker then signs in to the real service [8]. CISA's standing advice is to check the URL for misspellings and click the padlock to inspect the certificate [c3ref]. That is precisely the check BitB counterfeits. CTM360 has also seen the technique aimed at interior ministries, with the genuine MOI Singapore site untouched while a fake one hosted the simulated browser [6].
For defenders, the exposure sits in the exception path. Microsoft Defender for Office 365 surfaces the detection technology behind a verdict, and the false-positive remedy is an admin submission plus a Tenant Allow/Block List entry that applies a temporary override to the filters [9]. An allow entry granted in a hurry for a plausible recruiting domain is the cheapest thing an attacker can buy.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Over two months, CTM360 identified more than 3,000 phishing URLs impersonating recruiters and hiring processes from over 50 organizations.
- [2]
The RecruitTrap campaign uses fake interview invitations, counterfeit scheduling portals, and Browser-in-the-Browser (BitB) login windows to steal corporate credentials and relay MFA challenges.
- [3]
The campaign primarily targets marketing professionals and filters for corporate email accounts, enabling credential theft and potential account takeover.
- [4]
A BitB phishing page uses JavaScript to create a simulated browser window that displays a URL of the attacker's choice, such as https://accounts.google.com or https://login.microsoftonline.com.
- [5]
In a BitB attack the simulated address bar shows the URL only as an image or text, and the full-screen display mode blocks the real site's URL, so the user may not notice the absence of SSL certificates or other security indicators.
- [6]
CTM360 observed ongoing BitB campaigns targeting ministries and government websites, specifically interior ministries; in the MOI Singapore case the official website remained unaffected while the threat actor ran a fake site containing a fake browser interface.
Sources & coverage · 3 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- ctm360.com6d agoRecruitTrap: Browser-in-the-Browser (BitB) Recruitment Scams
- ctm360.com6d agoBrowser-in-the-Browser (BitB) Attack Explained | CTM360



