Home Cyber Security News Gmail Credential Phishing Campaign Uses Nested Redirects Across Legitimate Platforms

Gmail Credential Phishing Campaign Uses Nested Redirects Across Legitimate Platforms

0
Gmail Phishing Uses Redirects
Gmail Phishing Uses Redirects

Cybercriminals have launched a highly targeted phishing campaign designed to steal Gmail credentials by offering fake job interviews at some of the world’s most recognized brands.

Attackers are sending personalized emails that appear to be from recruiters seeking to hire professionals for marketing roles. These messages address the targets by name and accurately reflect their current industry or job title.

This level of personalization suggests the threat actors are conducting thorough background research before launching their attacks.

The primary goal of this operation is to trick victims into clicking a malicious link to book an interview, ultimately leading them to surrender their account passwords.

To bypass modern email security filters, the attackers rely on a complex chain of nested redirects across multiple legitimate platforms.

The attack sequence starts with a phishing email sent through PeopleForce (peopleforce[.]io), a genuine cloud-based Human Resource Management and Applicant Tracking System.

Because it originates from a trusted HR domain, the initial message easily slips past standard email security gateways and lands directly in the victim’s inbox.

Gmail Phishing Uses Redirects (Source: github)
Gmail Phishing Uses Redirects (Source: github)

Gmail Phishing Uses Redirects

Once the eager job seeker clicks the link to schedule their interview, the redirect chain activates. The original link first points to Salesforce Marketing Cloud, also known as ExactTarget (exct[.]net).

Upon reaching the final landing page, the victim encounters a sophisticated credential harvesting mechanism. The phishing site utilizes a Browser-in-the-Browser (BitB) pop-up that perfectly mimics a legitimate Google login window.

This technique is highly effective because it creates an interactive fake window within the main web page. The pop-up displays a forged URL bar and a fake security padlock, tricking even cautious users into entering their credentials.

Github said, impersonating highly desirable employers across various industries to maximize the lure’s effectiveness. The attackers have systematically registered numerous lookalike domains to make their fake hiring portals appear genuine.

Gmail Phishing Uses Redirects (Source: github)
Gmail Phishing Uses Redirects (Source: github)

Targeted sectors include major airlines, global food and beverage conglomerates, luxury apparel brands, management consulting firms, and massive sporting organizations.

Fake opportunities at premium brands such as Coca-Cola, Delta Air Lines, Adidas, Netflix, OpenAI, and FIFA are luring job seekers.

Because the job market remains highly competitive, users are often less suspicious when approached by recruiters from these prestigious companies.

To defend against this sophisticated campaign, security teams are strongly advised to block known infrastructure and monitor network traffic for the following lookalike domains.

Indicators of Compromise

Indicator of Compromise (Domain)Targeted BrandIndustry
aa-careers[.]comAmerican AirlinesAirlines & Travel
booking-careers[.]comBooking.comAirlines & Travel
jobs-delta[.]comDelta Air LinesAirlines & Travel
delta-careers[.]comDelta Air LinesAirlines & Travel

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here