Researchers identified a significant global phishing operation targeting cybersecurity professionals. Compromised marketing accounts can grant unauthorized access to advertising networks, corporate social media sites, customer information, emails, and crucial business tools. The Svelte/SvelteKit front end tricked victims into navigating through stages designed to bypass CAPTCHA, username entry, password submission, and multiple two-factor authentication methods, including OTP verification, phone number matching, and suffix checks.
Across 813 unique registered domains, the most frequently encountered top-level domain was .cfd, appearing in 40% of cases, followed by .com at 25.1%, .info at 15.1%, .works at 10.5%, and .work at 6.3%. The campaign aims for swift rebranding, allowing modifications by altering employer names, recruiters' identities, backgrounds, slogans, and authentication providers while keeping the same 30-minute meeting and login procedures intact.
Organizations can minimize exposure by using phishing-resistant authentication methods like passkeys or hardware-backed WebAuthn, monitoring for lookalike recruitment domains, and correlating suspicious recruitment emails with unusual sign-in attempts or new sessions. If you entered credentials or an MFA code into a suspected recruitment page, immediately change your password, revoke active sessions and tokens, review sign-in activity, mailbox rules, and OAuth grants, and notify your security team. It begins by establishing legitimacy through a deceptive browser window, which then leverages this trust to facilitate credential theft, bypass Multi-Factor Authentication (MFA), and ultimately achieve account takeover.












