Cybercriminals are constantly evolving their methods of deception, now exploiting the credibility of well-known businesses to trap unsuspecting professionals. A new, highly organized phishing has targeted marketing workers, using fake job offers that appear to come from more than 30 major companies, including Adobe, Netflix, Coca-Cola and OpenAI.

The aim of the attack is not to send malware, but to steal login details for Google accounts, which are often used to access corporate data, cloud services and collaboration tools.
How the scam works
According to analysis by cybersecurity researcher Will Thomas from Team Cymru, the attack begins with a highly convincing email from a purported recruiter. The message informs the recipient that they have been selected for a potential marketing job and invites them to schedule an online interview.
See also: Microsoft Teams: Fake IT support calls lead to EtherRAT distribution
To increase the credibility of the scam, attackers use real names and photos of HR executives who work for the companies they are impersonating. This makes the email look completely legitimate and reduces the chances that the recipient will suspect it is a trap.
Exploitation of legitimate cloud services
One of the most interesting elements of the campaign is the misuse of well-known online services. The perpetrators leverage the PeopleForce, while also using domains associated with Salesforce Marketing Cloud, creating a chain of successive redirects before leading the victim to the final phishing page.
This technique makes it significantly more difficult for both users and security filters, as much of the path is taken through legitimate services. This makes the links appear more trustworthy and has a greater chance of bypassing email protection mechanisms.
The Browser-in-the-Browser technique
After the user clicks the link to schedule the interview, they are taken to a website that mimics the official Google login process. There, a fake “Continue with Google” pop-up appears, which looks almost identical to the authentic one.
See also: BusySnake Stealer: The Russian-Speaking APT That Hits Energy and Government
In reality, however, this is not a real browser window. Attackers use the Browser-in-the-Browser (BitB) technique, creating a completely convincing imitation of a login window with HTML and CSS. The user believes that they are entering their details into Google, but these are sent directly to the cybercriminals.
Modern web development technologies allow perpetrators to copy every element of the authentic environment with great precision, from icons to address bars and control buttons.

Dozens of well-known companies in the spotlight
Researchers identified at least 34 different domains that imitate companies from many industries, including aviation, technology, retail, food, hospitality, and entertainment.
Among the names used are American Airlines, Booking.com, Delta Air Lines, United Airlines, PepsiCo, Red Bull, Adidas, Louis Vuitton, Sephora, Levi's, Marriott, FIFA, Netflix, Adobe, McKinsey, ManpowerGroup and OpenAI. The choice of such well-known brands significantly increases the credibility of the scam and enhances its success rates.
What users should watch out for
This campaign demonstrates that phishing attacks are becoming increasingly sophisticated, no longer relying on crude or poorly written messages. Instead, they leverage real company credentials, legitimate cloud services, and advanced deception techniques to fool even experienced users.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Prompt Injection: AI agents make crypto payments without authorization
Experts recommend paying close attention to any emails that claim to be job offers or requests to log in to Google accounts. Before entering credentials, it’s important to carefully check the website address, avoid logging in via suspicious links, and use two-factor authentication (2FA). In an era where cybercriminals are exploiting even trusted services to hide their tracks, awareness and vigilance remain the most effective line of defense.
Source: www.bleepingcomputer.com
