Phishing poses as big-brand job interview to steal Google accounts

Phishing Campaign Targets Marketing Pros with Fake Job Interviews, Steals Google Accounts

A sophisticated phishing campaign has been uncovered, using over 30 well-known brands to trick marketing professionals into handing over their Google account credentials. The operation is particularly insidious, as it leverages legitimate cloud-based platforms and domain names associated with major companies like Salesforce and PeopleForce to increase its chances of success.

The threat actor behind this campaign is impersonating recruiters from top brands in various sectors, including airlines, food and beverage, apparel, staffing, consulting, hospitality, entertainment, and sports. The email purports to be a job interview invitation, complete with the name and picture of a real recruiter, making it difficult for victims to distinguish between genuine and fake.

But how does this phishing campaign work? According to security researcher Will Thomas from Team Cymru, the operation relies on nested redirects – a technique that routes visitors through multiple legitimate services before reaching a malicious landing page. In this case, the links in the phishing email appear to originate from PeopleForce, but resolve to a domain operated by Salesforce (exct[.]net). This domain then forwards the visitor to a cloud-based real estate CRM software called Wise Agent, which ultimately leads to the phishing landing page.

The campaign’s success lies in its ability to mimic legitimate authentication pop-up pages. By using modern web development tools, the attacker can imitate all the elements of a genuine Google sign-in popup, making it difficult for victims to distinguish between real and fake. This technique is known as “browser-in-the-browser” (BitB), where the attacker uses HTML and CSS code rendered inside the phishing page to create a convincing authentication experience.

While it’s unclear how the threat actor gained access to these legitimate platforms, it’s possible that they created genuine accounts specifically for this campaign or used compromised logins. This highlights the importance of implementing robust security measures, including regular monitoring and testing of SIEM and EDR rules.

The takeaway from this phishing campaign is clear: security teams must be vigilant in their efforts to detect and prevent attacks. By regularly testing every layer of their defenses, organizations can reduce the likelihood of successful attacks slipping through the net. As Will Thomas noted, “test every layer before attackers do.”


Source: Bleeping Computer — 2026-07-06