Mobile-Focused Recruitment Scams Target Corporate Credentials

Security researchers at Zimperium have uncovered a sophisticated phishing campaign that uses fake recruitment websites to harvest corporate credentials, with particular emphasis on users accessing job opportunities from mobile devices. The activity, tracked as RecruitTrap, impersonates well-known organisations including Amazon, Apple, Boeing, Deloitte, Emirates Group, Heineken, Lego and Louis Vuitton through convincing recruitment-themed domains. Unlike traditional phishing campaigns that cast a wide net, RecruitTrap is specifically designed to identify and target business users. The phishing sites perform a pre-screening process that rejects personal email addresses and only allows corporate accounts to continue through the fake application process. This selective approach indicates that attackers are seeking access to enterprise environments rather than individual consumer accounts.
A notable feature of the campaign is its mobile-first design. While desktop users may encounter a browser-in-the-browser (BitB) authentication prompt, mobile users are presented with a full-screen counterfeit login page that conceals browser elements such as the address bar. By removing these visual indicators, attackers make it more difficult for victims to verify the legitimacy of the website before entering their credentials.
The objective is not simply password theft. Corporate accounts often provide access to email, cloud applications, collaboration platforms and OAuth tokens, creating opportunities for further compromise. Once authenticated, attackers may be able to access sensitive business information, conduct business email compromise (BEC) activity, or use trusted accounts to launch additional phishing attacks against colleagues and partners.
Zimperium's investigation identified 46 previously unpublished indicators of compromise (IOCs) and found that the malicious infrastructure remained active across multiple legitimate hosting and domain providers. Rather than frequently changing infrastructure to avoid detection, the threat actors relied on established cloud and domain services, including networks associated with Amazon and SEDO. This persistence can allow phishing domains to remain operational long enough to evade traditional URL blocklists and reputation-based security controls.
The campaign reflects a broader trend highlighted across open-source threat intelligence reporting. Recruitment-themed phishing continues to be highly effective because it leverages trusted brands, professional networking platforms and genuine job-seeking activity. As organisations increasingly rely on cloud-based services and remote working practices, corporate identities have become a primary target for cyber criminals seeking initial access into enterprise environments.
The National Cyber Security Centre (NCSC) recommends a layered approach to defending against phishing attacks, combining technical controls with user awareness rather than relying solely on employees to identify malicious messages.
To reduce the risk posed by recruitment-themed phishing campaigns, organisations should:
Enforce multi-factor authentication (MFA) across all externally accessible services, preferably using phishing-resistant authentication methods.
Implement SPF, DKIM and DMARC to help prevent email spoofing and improve protection against phishing attacks.
Encourage staff to independently verify recruitment opportunities and exercise caution when entering corporate credentials after following links from emails, text messages or social media platforms.
Secure mobile devices through effective device management, regular patching and monitoring for suspicious authentication activity.
Maintain incident response procedures that allow compromised accounts to be identified, contained and reset quickly if credentials are stolen.
As phishing campaigns become increasingly tailored to mobile users and business identities, organisations should focus on strengthening identity security alongside traditional email and web security controls. The ability of attackers to convincingly imitate recruitment processes demonstrates that credential protection, MFA and employee vigilance remain critical defences against modern phishing threats.



