Summary is AI-generated, newsdesk-reviewed
  • Zimperium's research reveals sophisticated phishing targeting corporate credentials via mobile devices.
  • Attacks impersonate recruiters, focusing on corporate access, exploiting mobile screen limitations.
  • 46 new IOCs identified, with phishing domains delaying detection in public threat feeds.

Zimperium has published new research exposing how cybercriminals utilise advanced phishing strategies to target corporate credentials, specifically through mobile devices.

These sophisticated campaigns impersonate recruiters and HR professionals from well-known companies, crafting realistic interview and scheduling scenarios to lure victims onto fake login pages. Remarkably, the phishing infrastructure is designed to reject personal email addresses and compel victims to submit corporate credentials, indicating a targeted attack on enterprise accounts.

Phishing tactics on different devices

On desktops, attackers often employ Browser-in-the-Browser (BitB) techniques to mimic legitimate authentication windows, making it difficult to distinguish fraud. On mobile devices, these attacks become even more challenging to detect. The phishing experience adapts to the smaller screen, presenting victims with full-screen counterfeit login pages. Due to the reduced visual cues on mobile, such as limited URL visibility, employees find it harder to identify fraudulent authentication requests.

Nico Chiaraviglio of Zimperium commented, “What makes these recruitment scams particularly concerning for enterprises is the deliberate focus on corporate identities. Attackers are not simply looking for any credential they can steal. They are screening for enterprise accounts that can provide a path into corporate email, cloud applications, and other business-critical systems. Mobile makes that deception even more effective because many of the visual signals employees rely on to recognise phishing are reduced or absent.”

Impersonation and detection challenges

Zimperium's analysis over the past year showed that the threat is not limited to current recruitment scams

Zimperium's analysis over the past year showed that the threat is not limited to current recruitment scams; it persists with attackers maintaining infrastructure while impersonating major organisations in sectors like technology, retail, and aviation. 

Their investigation uncovered 46 new indicators of compromise related to these activities. Moreover, their study revealed significant delays in the identification of impersonation domains by public threat intelligence feeds, with some domains going undetected for extended periods, thereby increasing the risk of employees encountering these malicious platforms.

Addressing mobile-centric security gaps

The study highlights a critical issue for enterprise security teams, as attacks on corporate identities frequently originate from mobile devices, beyond the scope of traditional desktop-centric security measures.

Zimperium's Mobile Threat Defence (MTD) system addresses this gap by dynamically analysing network activities and mobile threats directly on the device. This enables organisations to identify and block credential-harvesting attacks in real-time, including new phishing infrastructures that may not yet be catalogued in static URL and reputation databases.

In case you missed it

Hikvision solution boosts Muçum flood preparedness
Hikvision solution boosts Muçum flood preparedness

When Brazil’s Taquari River threatens to overflow, the Municipality of Muçum no longer waits and watches—it knows. Using Hikvision’s water-level detection...

Responsible AI adoption starts with governance
Responsible AI adoption starts with governance

The eagerness to adopt AI in physical security is increasing as teams want to implement technology solutions for faster, smarter operations. At the same time, the conversations sur...

Solink's AI agents boost efficiency of existing infrastructure with automation
Solink's AI agents boost efficiency of existing infrastructure with automation

Deploying artificial intelligence (AI) tools should be seen as a business initiative rather than a technology initiative, says Martin Soukup, CTO of Solink, a cloud-based video sec...