Red Bull-Themed Scams Trick Job Seekers into Giving Up Credentials

Threat actors are using advanced infrastructure and brand impersonation techniques to get past standard enterprise email defenses, according to a recent phishing campaign made public by Evalian’s Security Operations Center (SOC).

Despite widespread adoption of email filtering, authentication protocols such as SPF, DKIM, and DMARC, and ongoing user awareness training, the attackers were able to deliver convincing phishing emails directly to user inboxes.

The campaign targeted job seekers with messages purporting to be from Red Bull, exploiting both human trust and technical loopholes to steal social media credentials.

Abuse of Trusted Platforms

The phishing emails appeared to originate from the legitimate address messaging-service@post.xero.com and passed all standard authentication checks, a method often referred to as “piggybacking” on trusted domains.

Phishing Attacks
email header 

These emails included a professionally worded invitation to apply for a Red Bull social media manager role enticingly plausible for unsuspecting recipients.

However, the embedded links directed users to a carefully orchestrated multi-stage attack chain.

First, recipients encountered a reCAPTCHA challenge, likely implemented to slow down automated security scanners.

Phishing Attacks
reCAPTCHA screen

This was followed by a fake job description page styled to mimic real job platforms, and finally, a fake Facebook login interface designed to exfiltrate credentials.

Technical analysis of the campaign revealed that while the front-end was served by a valid Let’s Encrypt TLS certificate making the site appear secure the underlying infrastructure used IPs and hosting providers with established histories of abuse and disposability.

TLS fingerprinting (using the JARM methodology) and passive DNS analysis exposed a web of related domains, all spun up within days of the campaign’s launch and hosted on low-reputation VPS services.

Some domains demonstrated clear attempts to spoof multiple brands, including not only Red Bull but also prominent influencers, indicating a broad, scalable phishing operation rather than a one-off attack.

Single Attack Turns into Community Defense

What set this incident apart was the human-led threat detection and rapid incident response undertaken by Evalian’s SOC.

An analyst identified the suspicious activity during a routine email review, even as automated tools failed to flag the message.

By leveraging open-source intelligence (OSINT), TLS certificate analysis, and infrastructure hunting, the SOC was able to map the attacker’s tactics, identify clusters of malicious infrastructure, and engineer custom detection queries.

These new detections were immediately deployed across Evalian’s customer base, transforming the indicators of compromise (IOCs) from this single campaign into proactive defenses for a wider community.

This case underscores the adaptability of modern adversaries, who are increasingly abusing trusted cloud-based platforms like Mailgun and SendGrid to deliver malicious content that passes routine security checks.

The operation’s sophistication demonstrates that technical controls alone are insufficient; continuous threat hunting and behavioral analysis remain essential in an effective defense strategy.

Evaluating trusted sender domains, scrutinizing certificate details, and correlating network, endpoint, and email telemetry are now indispensable practices for modern SOCs.

Indicators of Compromise (IOCs)

TypeValue
Domaincharliechaplin7eont[.]space
Domain*.apply-to-get-hired[.]com
Domainuser0212-stripe[.]com
IP Address38.114.120[.]167
ASN63023 (AS-GLOBALTELEHOST)
TLS Cert CNbot2shimeta.charliechaplin7eont.space
JARM Fingerprint27d40d40d00040d00042d43d000000d2e61cae37a985f75ecafb81b33ca523
Mail Sendermessaging-service@post.xero[.]com
Reply-Tored.bull.crew@srbs.user0212-stripe[.]com

Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant updates

Mandvi
Mandvi
Mandvi is a Security Reporter covering data breaches, malware, cyberattacks, data leaks, and more at Cyber Press.

Trending News

Related Stories