HomeSecurityPhishing campaign impersonates leading companies and steals Google accounts

Phishing campaign impersonates leading companies and steals Google accounts

Cybercriminals are constantly evolving their methods of deception, now exploiting the credibility of well-known businesses to trap unsuspecting professionals. A new, highly organized phishing has targeted marketing workers, using fake job offers that appear to come from more than 30 major companies, including Adobe, Netflix, Coca-Cola and OpenAI.

Phishing Google accounts

The aim of the attack is not to send malware, but to steal login details for Google accounts, which are often used to access corporate data, cloud services and collaboration tools.

How the scam works

According to analysis by cybersecurity researcher Will Thomas from Team Cymru, the attack begins with a highly convincing email from a purported recruiter. The message informs the recipient that they have been selected for a potential marketing job and invites them to schedule an online interview.

See also: Microsoft Teams: Fake IT support calls lead to EtherRAT distribution

To increase the credibility of the scam, attackers use real names and photos of HR executives who work for the companies they are impersonating. This makes the email look completely legitimate and reduces the chances that the recipient will suspect it is a trap.

Exploitation of legitimate cloud services

One of the most interesting elements of the campaign is the misuse of well-known online services. The perpetrators leverage the PeopleForce, while also using domains associated with Salesforce Marketing Cloud, creating a chain of successive redirects before leading the victim to the final phishing page.

This technique makes it significantly more difficult for both users and security filters, as much of the path is taken through legitimate services. This makes the links appear more trustworthy and has a greater chance of bypassing email protection mechanisms.

The Browser-in-the-Browser technique

After the user clicks the link to schedule the interview, they are taken to a website that mimics the official Google login process. There, a fake “Continue with Google” pop-up appears, which looks almost identical to the authentic one.

See also: BusySnake Stealer: The Russian-Speaking APT That Hits Energy and Government

In reality, however, this is not a real browser window. Attackers use the Browser-in-the-Browser (BitB) technique, creating a completely convincing imitation of a login window with HTML and CSS. The user believes that they are entering their details into Google, but these are sent directly to the cybercriminals.

Modern web development technologies allow perpetrators to copy every element of the authentic environment with great precision, from icons to address bars and control buttons.

Google account logout secure access

Dozens of well-known companies in the spotlight

Researchers identified at least 34 different domains that imitate companies from many industries, including aviation, technology, retail, food, hospitality, and entertainment.

Among the names used are American Airlines, Booking.com, Delta Air Lines, United Airlines, PepsiCo, Red Bull, Adidas, Louis Vuitton, Sephora, Levi's, Marriott, FIFA, Netflix, Adobe, McKinsey, ManpowerGroup and OpenAI. The choice of such well-known brands significantly increases the credibility of the scam and enhances its success rates.

What users should watch out for

This campaign demonstrates that phishing attacks are becoming increasingly sophisticated, no longer relying on crude or poorly written messages. Instead, they leverage real company credentials, legitimate cloud services, and advanced deception techniques to fool even experienced users.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Prompt Injection: AI agents make crypto payments without authorization

Experts recommend paying close attention to any emails that claim to be job offers or requests to log in to Google accounts. Before entering credentials, it’s important to carefully check the website address, avoid logging in via suspicious links, and use two-factor authentication (2FA). In an era where cybercriminals are exploiting even trusted services to hide their tracks, awareness and vigilance remain the most effective line of defense.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS