Phishing

Fake recruiter scams target corporate credentials on mobile devices

Man hands checking smart phone at night

Infosecurity Magazine reports that fake recruiter scams are increasingly targeting corporate credentials on mobile devices, employing sophisticated tactics like full-screen login pages and pre-qualification checks to specifically harvest enterprise accounts.

Researchers at Zimperium's zLabs have identified these campaigns, tracked as RecruitTrap, impersonating major companies such as Amazon, Apple, and Deloitte. The attacks utilize full-screen counterfeit login pages on mobile devices, removing browser elements to hinder user detection. A key tactic involves screening submitted information, rejecting personal email addresses and demanding corporate credentials, indicating a focus on accounts with access to sensitive enterprise resources. Attackers aim to obtain OAuth tokens, potentially leading to unauthorized access to internal communications and cloud applications, facilitating further network intrusion.

The infrastructure behind these scams has shown persistence across various cloud, hosting, and domain-parking providers, including Amazon and SEDO. This persistence allows new lookalike domains to remain operational before being added to threat intelligence feeds, posing a challenge for traditional URL blocklists. Zimperium recommends securing corporate identities at the mobile touchpoint and dynamically inspecting network traffic to counter these credential-harvesting attempts.

Source: Infosecurity Magazine

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds