Attackers are running a large-scale phishing campaign that impersonates recruiters from more than 30 major brands to steal Google account credentials, primarily from job seekers and marketing professionals. The emails use real recruiters’ names and photos and direct victims to fake interview scheduling or career pages, including a confirmed fake McKinsey & Company careers site hosted on Netlify, before presenting a browser-in-the-browser Google sign-in prompt designed to capture Gmail logins.
The operation relies on a nested redirect chain through legitimate business services including PeopleForce, Salesforce Marketing Cloud infrastructure on exct.net, and Wise Agent to make the phishing flow appear trustworthy and evade detection. Researchers said the campaign has been active for at least five months and spans brands across consulting, technology, retail, travel, hospitality, entertainment, and consumer goods, while noting that abuse of those platforms does not necessarily indicate the services themselves were compromised.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Reporting revealed that the campaign abuses legitimate services in a multi-stage redirect chain involving PeopleForce, Salesforce Marketing Cloud infrastructure on exct.net, and Wise Agent before sending victims to attacker-controlled phishing pages. A confirmed example used a fake McKinsey & Company careers page hosted on Netlify and real recruiter identities to increase credibility.
Researchers said a phishing campaign impersonating more than 30 major brands in fake job interview and recruiting emails has been active for at least five months. The operation targets marketing professionals and job seekers with fake career pages and browser-in-the-browser Google sign-in prompts to steal Gmail credentials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcetechrepublic.com
Open sourcecybersecuritynews.com
Open sourcecysecurity.news
Open sourcebleepingcomputer.com
Open sourcegist.github.com
Open sourcebitdefender.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.