25 Aug 2026

Zimperium, the pioneer in AI-empowered mobile security, releases new research revealing how threat actors are using sophisticated recruitment-themed phishing campaigns to specifically target corporate credentials, with mobile devices creating an especially effective attack surface.

The campaigns impersonate recruiters and HR personnel from well-known global brands, using realistic interview and scheduling experiences to lure victims into counterfeit login pages. Critically, the phishing infrastructure actively rejects personal email addresses and requires victims to enter corporate credentials, demonstrating that these attacks are intentionally designed to compromise enterprise accounts rather than indiscriminately harvest consumer credentials.

Legitimate authentication windows

On desktop devices, attackers can use Browser-in-the-Browser (BitB) techniques to simulate legitimate authentication windows. On mobile, the attack becomes even harder to identify. The phishing experience adapts to the smaller screen and presents victims with a full-screen counterfeit login page. With limited visibility into URLs and other browser indicators, employees can have fewer visual cues that the authentication request is fraudulent.

What makes these recruitment scams particularly concerning for enterprises is the deliberate focus on corporate identities,” said Nico Chiaraviglio at Zimperium. “Attackers are not simply looking for any credential they can steal. They are screening for enterprise accounts that can provide a path into corporate email, cloud applications and other business-critical systems. Mobile makes that deception even more effective because many of the visual signals employees rely on to recognise phishing are reduced or absent.”

Impersonating prominent organisations

Zimperium analysed a year of telemetry associated with brand-impersonating recruitment domains and found that the threat extends beyond the recent surge in recruitment scams. Attackers have maintained persistent infrastructure while impersonating prominent organisations across technology, retail, aviation, professional services, consumer goods and other industries.

As part of its investigation, Zimperium identified 46 previously unpublished indicators of compromise (IOCs) associated with this activity. The analysis also found significant delays between the registration of impersonation domains and their identification by public threat feeds. In several cases, domains remained unreported for months or even years, creating an extended window in which employees could encounter malicious infrastructure before it appeared on traditional blocklists.

Desktop-centric security controls

The findings underscore a broader challenge for enterprise security teams: attacks targeting corporate identity increasingly begin on mobile devices, outside the visibility of desktop-centric security controls.

Zimperium Mobile Threat Defence (MTD) dynamically analyses network activity and mobile threats directly at the device level, helping organisations identify and block credential-harvesting attacks in real time, including newly created phishing infrastructure that may not yet appear in static URL and reputation feeds.