← Back
PhishingHelp Net Security·3 hours ago

Bogus recruiters go after high-value corporate credentials on mobile

Threat actors impersonating HR recruiters are targeting corporate credentials through fake interview scheduling flows on mobile devices, leveraging scraped public profile data to increase credibility. The attackers employ browser-in-the-browser (BitB) techniques to create convincing phishing pages that bypass user skepticism and extract corporate passwords from high-value targets.

Read full article at Help Net Security

Related Articles

PhishingThe Hacker News·7 hours ago

Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes

Researchers have uncovered a phishing-as-a-service platform called AnonyMousKIT that uses AI voice agents to impersonate Apple Support and target owners of stolen devices, attempting to extract passcodes and two-factor authentication codes to bypass Activation Lock. The credit-metered service automates social engineering attacks by calling victims and deceiving them into revealing sensitive authentication credentials. This approach represents an evolution in device theft operations, combining AI-driven voice phishing with stolen device monetization tactics.

PhishingThe Hacker News·1 day ago

Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication. According to ANY.RUN research, 48% of targeted email addresses were potentially compromised. Most of the affected companies are US-based. Mirage2FA Campaign

PhishingThe Hacker News·1 day ago

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. "While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn't do harm, the threat actor’s use of npm isn't to infect developers who install it, but to use the