Zimperium has published new research exposing how cybercriminals utilise advanced phishing strategies to target corporate credentials, specifically through mobile devices.
These sophisticated campaigns impersonate recruiters and HR professionals from well-known companies, crafting realistic interview and scheduling scenarios to lure victims onto fake login pages. Remarkably, the phishing infrastructure is designed to reject personal email addresses and compel victims to submit corporate credentials, indicating a targeted attack on enterprise accounts.
Phishing tactics on different devices
On desktops, attackers often employ Browser-in-the-Browser (BitB) techniques to mimic legitimate authentication windows, making it difficult to distinguish fraud. On mobile devices, these attacks become even more challenging to detect. The phishing experience adapts to the smaller screen, presenting victims with full-screen counterfeit login pages. Due to the reduced visual cues on mobile, such as limited URL visibility, employees find it harder to identify fraudulent authentication requests.
Nico Chiaraviglio of Zimperium commented, “What makes these recruitment scams particularly concerning for enterprises is the deliberate focus on corporate identities. Attackers are not simply looking for any credential they can steal. They are screening for enterprise accounts that can provide a path into corporate email, cloud applications, and other business-critical systems. Mobile makes that deception even more effective because many of the visual signals employees rely on to recognise phishing are reduced or absent.”
Impersonation and detection challenges
Zimperium's analysis over the past year showed that the threat is not limited to current recruitment scams
Zimperium's analysis over the past year showed that the threat is not limited to current recruitment scams; it persists with attackers maintaining infrastructure while impersonating major organisations in sectors like technology, retail, and aviation.
Their investigation uncovered 46 new indicators of compromise related to these activities. Moreover, their study revealed significant delays in the identification of impersonation domains by public threat intelligence feeds, with some domains going undetected for extended periods, thereby increasing the risk of employees encountering these malicious platforms.
Addressing mobile-centric security gaps
The study highlights a critical issue for enterprise security teams, as attacks on corporate identities frequently originate from mobile devices, beyond the scope of traditional desktop-centric security measures.
Zimperium's Mobile Threat Defence (MTD) system addresses this gap by dynamically analysing network activities and mobile threats directly on the device. This enables organisations to identify and block credential-harvesting attacks in real-time, including new phishing infrastructures that may not yet be catalogued in static URL and reputation databases.
Zimperium, the pioneer in AI-empowered mobile security, releases new research revealing how threat actors are using sophisticated recruitment-themed phishing campaigns to specifically target corporate credentials, with mobile devices creating an especially effective attack surface.
The campaigns impersonate recruiters and HR personnel from well-known global brands, using realistic interview and scheduling experiences to lure victims into counterfeit login pages. Critically, the phishing infrastructure actively rejects personal email addresses and requires victims to enter corporate credentials, demonstrating that these attacks are intentionally designed to compromise enterprise accounts rather than indiscriminately harvest consumer credentials.
Legitimate authentication windows
On desktop devices, attackers can use Browser-in-the-Browser (BitB) techniques to simulate legitimate authentication windows. On mobile, the attack becomes even harder to identify. The phishing experience adapts to the smaller screen and presents victims with a full-screen counterfeit login page. With limited visibility into URLs and other browser indicators, employees can have fewer visual cues that the authentication request is fraudulent.
“What makes these recruitment scams particularly concerning for enterprises is the deliberate focus on corporate identities,” said Nico Chiaraviglio at Zimperium. “Attackers are not simply looking for any credential they can steal. They are screening for enterprise accounts that can provide a path into corporate email, cloud applications and other business-critical systems. Mobile makes that deception even more effective because many of the visual signals employees rely on to recognise phishing are reduced or absent.”
Impersonating prominent organisations
Zimperium analysed a year of telemetry associated with brand-impersonating recruitment domains and found that the threat extends beyond the recent surge in recruitment scams. Attackers have maintained persistent infrastructure while impersonating prominent organisations across technology, retail, aviation, professional services, consumer goods and other industries.
As part of its investigation, Zimperium identified 46 previously unpublished indicators of compromise (IOCs) associated with this activity. The analysis also found significant delays between the registration of impersonation domains and their identification by public threat feeds. In several cases, domains remained unreported for months or even years, creating an extended window in which employees could encounter malicious infrastructure before it appeared on traditional blocklists.
Desktop-centric security controls
The findings underscore a broader challenge for enterprise security teams: attacks targeting corporate identity increasingly begin on mobile devices, outside the visibility of desktop-centric security controls.
Zimperium Mobile Threat Defence (MTD) dynamically analyses network activity and mobile threats directly at the device level, helping organisations identify and block credential-harvesting attacks in real time, including newly created phishing infrastructure that may not yet appear in static URL and reputation feeds.