Press play to start listening
A convincing job invitation can lead directly to a fake corporate sign-in page. The phishing campaign, tracked as RecruitTrap, impersonates recruiters from major companies and adapts its login pages when targets open them on mobile devices.
Cybersecurity firm CTM360 documented more than 3,000 phishing URLs that impersonated recruitment processes across more than 50 organizations during a two-month investigation. According to the company’s analysis, marketing professionals were among the main targets, and the sites were designed to collect corporate credentials.
Now, Zimperium’s follow-up analysis has identified RecruitTrap domains impersonating Amazon, Louis Vuitton, Apple, FIFA, Emirates Group, Boeing, Heineken, Deloitte, and Lego. These companies were used as lures; Zimperium did not report that their systems were breached or that their real recruiters participated.
How RecruitTrap Works on Mobile Devices
The attack begins with a message from someone posing as an HR representative. Using details taken from public profiles, the scammer can mention the person’s name, job title, or employer, making the interview invitation seem genuine before sending them to a fake scheduling portal.
On a desktop or laptop, the link opens what appears to be a normal Microsoft or corporate sign-in window. It is actually a fake window drawn inside the phishing page, a method known as Browser-in-the-Browser, or BitB.
On a phone, the phishing kit changes its presentation. Zimperium’s mobile analysis found that it removes the simulated desktop window and displays a full-screen fake login page. With no browser frame or visible address bar, the person has almost nothing on screen to show that the login page is fake.
It is worth noting that the kit does not accept every email address; personal accounts may be rejected, while addresses that appear to belong to a company advance to the next stage. This shows that the operators are pursuing workplace access, not general consumer accounts.
Once a corporate username and password have been entered, the attackers can relay multifactor authentication requests through the fake portal. Successful access could expose email, internal messages, cloud applications, and OAuth tokens available to the compromised account.
Impersonation Domains Avoid Detection for Months
Zimperium examined one year of mobile telemetry and found that RecruitTrap-style domains often followed predictable formats, such as and (company)-careers.com(company)-global.com.
Some domains remained absent from public threat feeds for long periods. The domain hbc-careers(.)com was registered in October 2019 but was not reported by the feeds examined until January 2026, a gap of 2,297 days. Another domain, insulet-careers(.)com, had a gap of 1,464 days, while xmtrading-global went 525 days before appearing in those feeds.(.)com
Those figures measure the time between domain registration and public-feed reporting. They do not prove that every domain served phishing content throughout the entire period.
Although the domains copied different companies, many pointed back to the same small group of cloud, hosting, and domain-parking networks. Amazon and SEDO GmbH appeared most often at the network-owner level, while recurring IP ranges included 91.195.240.0/22 and 13.52.128.0/18.
This does not mean either provider was compromised or knowingly involved; it shows that the scammers repeatedly used infrastructure available through their networks.
Zimperium published 46 previously unreported indicators connected with the campaign. Companies can use the domains and network details to search mobile, DNS, and web-filtering records for related activity.
Employees receiving unexpected recruitment messages, especially on LinkedIn, should verify the sender through the company’s official careers website or another known contact method. Corporate credentials should be entered through an employer’s saved sign-in page or approved authentication app, not through a link supplied by an unfamiliar recruiter.
