HomeSecurityFake Google recruiters steal login details

Fake Google recruiters steal login details

A sophisticated phishing campaign has emerged, targeting prospective employees through fake Google job openings . Attackers are leveraging social engineering techniques to extract Gmail credentials and personal information .

Fake Google recruiters

This malicious enterprise exploits the trust associated with Google’s reputation by creating convincing recruitment emails that direct victims to fake login portals designed to collect identifying information. Cybercriminals pretend to be representatives HR Google, offering attractive career opportunities. These deceptive messages contain carefully crafted job descriptions and application processes that appear legitimate, with a formal appearance and professional communication style that mirrors authentic Google recruitment correspondence.

Cybersecurity researcher g0njxa spotted this campaign while investigating broader patterns of credential theft operations targeting large technology companies.

See also: MatrixPDF: New kit turns PDFs into phishing and malware baits

The researcher's analysis revealed that threat actors are using multiple attack variations, adapting their techniques to evade detection while maintaining high success rates.

Phishing: Fake Google recruiters target prospective employees

The malicious campaign demonstrates sophisticated evasion capabilities through the abuse of Extended Validation certificates across multiple platforms. The threat actors have obtained legitimate Apple Developer ID certificates with names such as “THOMAS BOULAY DUVAL” and “Alina Balaban,” allowing their malicious applications to bypass the original security mechanisms.

Signed DMG files are not detected on VirusTotal.

Fake Google recruiters steal login details

Analysis of malicious launchers reveals deliberate attempts to legitimize applications by embedding signer names in identifier strings, following patterns such as “thomas.parfums” which corresponds to “Thomas Boulay Duval”.

Mach -O binaries contain embedded references that link to remote AppleScript payloads, using the Odyssey Stealer framework for credential harvesting operations.

The campaign infrastructure includes compromised domains, such as franceparfumes[.]org, that host malicious scripts, with command and control servers operating from the IP address 185.93.89.62. These certificates represent significant financial investments for cybercriminals, as Apple's developer certification process involves significant time and cost, making their eventual revocation detrimental to ongoing malware operations.

See also: Android banking trojan uses VNC server to remotely control devices

Recruitment – ​​Scams

The new trend in recruitment fraud reveals a disturbing pattern: attackers are investing in “professional” presentation and technological means to make the scam look completely legitimate — and this is changing the rules of defense. Instead of limiting themselves to mass spam, attackers are building multi-layered campaigns that combine social engineering, seemingly legitimate credentials, and infrastructure that looks like real employers. The result: victims are less questionable, open attachments or enter credentials on fake portals, and attackers gain access to valuable communication and cloud platforms.

Defensively, a tailored approach that combines technology, processes, and human vigilance. At the email infrastructure level, organizations should tighten DMARC/DKIM/SPF, implement sender authentication checks, and enable sandboxing for links and attachments. At the endpoint, EDR solutions and behavior detection systems can catch strange processes related to loaders or credential extraction methods. Adopting phishing-resistant MFA — such as FIDO2 passkeys or hardware tokens — can help significantly.

See also: APT35 hackers attack government and military organizations

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Fake Google recruiters steal login details

For software platforms and application ecosystems, misuse of legitimate certificates exposes gaps in the identity assessment of issuers. Stricter identity issuance controls, periodic verifications, and a faster mechanism for revoking certificates when misuse is detected are needed. In addition, software providers must improve the transparency of notarization processes and offer easy tools for checking the origin of applications.

At the human factor level, training should focus on highly realistic scenarios: recruiter verification through official channels, domain checking, and offer confirmation through multiple independent means. Finally, collaboration between technology companies, recruitment platforms, and law enforcement will accelerate infrastructure recalls and legal actions — and this is critical to making the business of targeted fraud economically unprofitable.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS