Hackers Posing as Google Careers Recruiter to Steal Gmail Login Details
An ongoing phishing campaign is targeting job seekers by impersonating Google Careers recruiters. The aim is to lure victims into providing their Gmail credentials through deceptive emails.
An ongoing phishing campaign is targeting job seekers by impersonating Google Careers recruiters. The aim is to lure victims into providing their Gmail credentials through deceptive emails.
Security researchers have identified a multi-stage attack utilizing Salesforce infrastructure, Cloudflare protection, and WebSocket command-and-control mechanisms to extract sensitive information from victims.
The emails originate from a spoofed Salesforce subdomain, claiming to offer exclusive Google Career opportunities. A “View the role” button in the email redirects users to a fraudulent Google Careers application portal hosted at apply[.]grecruitingwise[.]com, behind Cloudflare protection.
Upon accessing the site, users are prompted to provide personal details, which are sent to satoshicommands[.]com. Subsequently, users are redirected to a fake Google sign-in page, where Gmail credentials are requested.
An ongoing phishing campaign is targeting job seekers by impersonating Google Careers recruiters.
The fraudulent portal uses a modified version of main.js to establish a WebSocket connection to hxxps://satoshicommands.com/ and communicates with the server through AJAX calls to /gw.php . The server issues commands for further actions, including OTP submission and phone verification.
apply[.]grecruitdigital[.]com apply[.]grecruitbridge[.]com apply[.]gtalentmatcher[.]com apply[.]gstafftalent[.]com apply[.]grecruitpro[.]com gcandidatespath[.]com gteamhirehub[.]com gteamlineup[.]com grecruitinglink[.]com getintouchwithcareers[.]com
Verify sender domains and confirm recruitment URLs on official company career pages. Hover over links to check the destination hostname before clicking. Avoid entering credentials on sites requiring captchas that you did not initiate. Enable two-factor authentication on Gmail and monitor for unusual login attempts.
Network defenders can block known malicious domains at the DNS level and employ email-gateway solutions to detect Salesforce subdomain spoofing. Regular sharing of threat intelligence and implementing indicator-blocking rules will help mitigate this threat.
As phishing tactics evolve to exploit trusted brands and infrastructure, maintaining layered defenses and user awareness training is critical to prevent credential-harvesting attacks.
Based on reporting by GBHackers.
