RecruitTrap

The Growing Threat of Browser-in-the-Browser (BitB) Recruitment Scams
hero background graphics
Technical illustration of the RecruitTrap phishing campaign showing fake recruiter invitations, Browser-in-the-Browser login windows, counterfeit recruitment portals, MFA interception, and credential theft workflow

Overview

CTM360’s RecruitTrap report exposes a global recruitment-themed phishing campaign using fake interview invitations, counterfeit scheduling portals, and Browser-in-the-Browser (BitB) login windows to steal corporate credentials and relay MFA challenges.
Over two months, CTM360 identified more than 3,000 phishing URLs impersonating recruiters and hiring processes from over 50 organizations. The campaign primarily targets marketing professionals and filters for corporate email accounts, enabling credential theft and potential account takeover.

Read the full report and explore CTM360’s latest insights and threat intelligence.