Cyber Attackers Pose as Top Brands to Steal Google Accounts, Targeting Marketing Professionals
A sophisticated phishing campaign has been uncovered, where attackers are impersonating over 30 well-known brands in fake job interviews to steal Google account credentials from marketing professionals. The operation is notable for its use of legitimate cloud-based platforms and domains associated with high-value companies to increase the chances of success.
The threat actor behind this campaign is abusing the PeopleForce human resources platform and a domain linked to Salesforce Marketing Cloud service, before redirecting the recipient to a malicious landing page. To further instill trust, the attacker is using the names and pictures of real recruiters at impersonated companies. For instance, a phishing email posing as a message from an Adidas recruiter asked the recipient to schedule a conversation about a potential role at the company.
One key aspect of this campaign is its reliance on nested redirects, a technique that routes visitors through multiple legitimate services before reaching the malicious landing page. According to Will Thomas, senior advisor at cybersecurity intelligence and threat hunting company Team Cymru, the underlying links resolve to the exct[.]net domain, which is operated by Salesforce following its acquisition of ExactTarget marketing automation platform.
The campaign has been ongoing for at least five months, with the initial emails using Outlook email addresses with the name of the impersonated company. The phishing landing page uses modern web development tools to imitate a legitimate Google sign-in popup, known as “browser-in-the-browser” (BitB). This technique allows the attacker to create an authentic-looking pop-up that prompts the victim to sign into their Google account.
While it is unclear how the threat actor gained access to the legitimate platforms, abusing them does not imply a compromise of the services. It’s possible that the attacker created a genuine account specifically for the campaign or used compromised logins to configure the redirect chain and landing page.
The impact of this phishing campaign is significant, as marketing professionals are often targeted due to their frequent use of Google accounts for work-related purposes. The attackers’ use of legitimate domains and platforms increases the likelihood that victims will trust the emails and click on the links, making it easier for them to steal sensitive information.
To avoid falling victim to such attacks, security teams must remain vigilant and test all layers of defense before attackers do. A recent study found that security teams log 54% of successful attacks and alert on just 14%, with the rest moving through their environment unseen. Conducting breach and attack simulation tests can help identify vulnerabilities in SIEM and EDR rules, preventing threats from slipping by detection.
In conclusion, this phishing campaign is a stark reminder of the importance of staying informed about emerging threats and taking proactive measures to protect against them. By being aware of these tactics and regularly testing our defenses, we can reduce the risk of falling victim to such attacks and keep our sensitive information secure.
Source: Bleeping Computer — 2026-07-06