HomeSecurityPhishing: Hackers impersonate HR departments to steal Gmail credentials

Phishing: Hackers impersonate HR departments to steal Gmail credentials

A sophisticated phishing campaign is targeting job seekers via Zoom 's legitimate document sharing features . The new attack shows how cybercriminals are exploiting trusted platforms to credentials Gmail harvest .

Phishing Gmail credentials

The attack leverages social engineering tactics, impersonating human resources departments and using authentic Zoom notifications to bypass traditional security measures and users' suspicions.

How does the malicious phishing campaign work?

The campaign begins with victims receiving emails legitimate-lookingHR Departments via Zoom Docs.” One of the subjects was: “HR Departments invited you to view 'VIEW DOCUMENTS'.” These messages bypass email authentication protocols, including SPF, DKIM, and DMARC verifications, making them appear completely legitimate to both users and security systems.

See also: New Phishing Kit automates the ClickFix attack process

Target individuals seeking employment

Attackers are strategically targeting individuals who are actively looking for work, taking advantage of their desire to respond to potential employment opportunities. Upon clicking on the Zoom document link, victims are redirected through a carefully orchestrated chain of malicious websites.

The initial redirect leads to overflow.qyrix.com.de , where the attackers have implemented a fake “bot protection” gateway, designed to serve a dual purpose: to block automated analysis security tools and create an illusion of legitimacy for unsuspecting users.

Phishing: Hackers impersonate HR departments to steal Gmail credentials

Himanshu Anand, a Cybersecurity Researcher, discovered this campaign while analyzing suspicious emails in his Inbox during a job search. His detailed investigation revealed the complex nature of the attack infrastructure and the credential extraction used by the threat actors.

See also: New Quishing attack targets Microsoft users

After users complete the fake CAPTCHA verification , they are redirected to a convincing Gmail phishing page hosted on the same malicious domain. The fake login interface closely mimics the authentic Google login portal, with correct branding, layout, and interactive elements that could fool even the most experienced users.

The most disturbing aspect of this campaign involves credential extraction real-time. Once victims enter their Gmail username and password on the phishing page, the stolen credentials are immediately transmitted to the attackers' command and control server via an active WebSocket connection at overflow.qyrix.com.de/websocket/socket.io/.

This real-time extraction method provides several advantages to cybercriminals. First, it allows for immediate verification of stolen credentials against Google’s authentication systems, allowing attackers to quickly identify which accounts they can successfully compromise. Second, the WebSocket protocol facilitates faster data transmission compared to traditional HTTP POST requests, reducing the opportunities for security systems to detect and block malicious activity.

See also: Hackers use 'Velociraptor' in ransomware attacks

Phishing: Hackers impersonate HR departments to steal Gmail credentials

The technical implementation reveals sophisticated programming knowledge, with the phishing infrastructure configured to handle multiple concurrent sessions and maintain persistent connections to victims' browsers. Network analysis shows that WebSocket traffic contains authentication tokens and session cookies, suggesting that the attackers are preparing for immediate account takeover attempts after stealing credentials.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS