Browser-in-the-Browser Phishing Campaign Impersonates 34+ Brands' Job Postings to Steal Google Account Credentials — Threadlinqs Intelligence
As of 2026-07-06, Browser-in-the-Browser Phishing Campaign Impersonates 34+ Brands' Job Postings to Steal Google Account Credentials is a high-severity phishing threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 37 indicators of compromise.
Threat ID: TL-2026-1139 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
A phishing operation active for at least five months impersonates recruiters from 34+ well-known brands (including American Airlines, Delta, Adidas, Adobe, Netflix, McKinsey, and OpenAI) to lure
This is a large-scale, brand-impersonation credential-phishing operation first publicly documented by Will Thomas (Senior Threat Intelligence Advisor, Team Cymru) and reported by BleepingComputer on 2026-07-06. The operation has been active for at least five months and targets marketing professionals by impersonating recruiters at 34+ recognizable global brands spanning airlines/travel (American Airlines, Delta Air Lines, United Airlines, Booking.com), food & beverage (Coca-Cola, PepsiCo, Red Bull), apparel/luxury (Adidas, Louis Vuitton, Sephora, Levi's), technology/staffing/consulting (Adobe, Aquent, ManpowerGroup, McKinsey & Company, OpenAI), hospitality/marketing (Marriott, Omnicom Group), and entertainment/sports (FIFA, Netflix).
Exploit-chain analysis: the lure begins with an email or calendar-style invitation posing as a job-interview scheduling request from a named, real employee at the impersonated brand (using genuine names and photos to build credibility). The initial link routes through PeopleForce, a legitimate HR/recruiting SaaS platform, whose links are abused to add an air of legitimacy and to launder the URL's reputation past link-reputation and secure-email-gateway scanners. From PeopleForce the victim is redirected a second time through exct.net, the tracking-link domain of Salesforce Marketing Cloud (formerly ExactTarget) — a widely-trusted, high-reputation SaaS domain frequently allow-listed by corporate mail filters, making it an attractive redirect hop for phishing-link laundering (a pattern independently documented by Okta Threat Intelligence and Sublime Security in adjacent recruiter-phishing campaigns using the same cl.sNN.exct.net tracking-link format). A third hop passes through wiseagent.com, a real-estate CRM platform, before finally landing on the attacker-controlled page (e.g. adidas-hiring[.]com for the Adidas lure, with equivalent '<brand>-hiring'-style domains for other impersonated brands).
The landing page itself does not use a real pop-up browser window. Instead it renders a Browser-in-the-Browser (BitB) fake authentication window entirely with HTML and CSS embedded in the phishing page — recreating a convincing fake browser chrome (address bar, padlock icon, and a 'Continue with Google' OAuth-style consent screen) that never actually opens a second browser process. This nested-iframe/CSS technique traces back to the BitB concept popularized publicly by security researcher mr.d0x in 2022 and has since been adopted broadly across the recruiter-phishing ecosystem (e.g. Push Security's Calendly-brand impersonation cluster and Okta's Meta-recruiter BitB cluster use the same fundamental rendering trick against Google/Facebook login flows). Because the fake window is rendered client-side, it defeats casual visual inspection and works even though the address bar shown to the victim is entirely fabricated. Victims who submit credentials into the fake Google form have their Google account credentials harvested directly by the attacker's backend.
No CVE or software vulnerability underlies this operation — it is a pure social-engineering and legitimate-infrastructure-abuse campaign ('living off trusted SaaS services') rather than an exploit against a coded flaw. The abused platforms (PeopleForce, Salesforce Marketing Cloud, Wise Agent) are not themselves compromised or vulnerable; their legitimate link/redirect and tracking functionality is being repurposed by the threat actor to build a chain of trust that defeats URL-reputation-based defenses. The operation remains unattributed to a named threat-actor group at time of reporting and is best classified as opportunistic/financially-motivated cybercriminal activity targeting Google Workspace/Gmail accounts held by marketing and advertising staff, whose accounts are valuable for downstream business email compromise, ad-account takeover, or resale.
This specific PeopleForce/exct.net/wiseagent.com chain sits within a much longer-running, well-documente
Target sectors: marketing, advertising, retail, aviation, hospitality, consumergoods, technology, fashion, foodandbeverage, consulting
Target regions: Global, North America, Europe
Detections & IOCs
As of 2026-07-25, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 37 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1589.002, T1591.004, T1583.001, T1584.006, T1585.002, T1608.005, T1566.002, T1204.001, T1078.004, T1656