Browser-in-the-Browser Phishing Campaign Impersonates 34+ Brands' Job Postings to Steal Google Account Credentials

Browser-in-the-Browser Phishing Campaign Impersonates 34+ (TL-2026-1139), also tracked as Big Brand Job Interview BitB Phishing Campaign, is a high-severity phishing campaign, first published 2026-07-06. It has no confirmed attribution, affects PeopleForce PeopleForce HR/Recruiting SaaS Platform, maps to 16 MITRE ATT&CK techniques (T1027, T1036.005, T1056.003), and is covered by 9 detection rules and 37 indicators of compromise.

Key facts for TL-2026-1139

Threat ID
TL-2026-1139
Also known as
Big Brand Job Interview BitB Phishing Campaign
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
2026-07-06
Last reviewed
2026-07-06
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
marketing, advertising, retail, aviation, hospitality, consumergoods, technology, fashion, foodandbeverage, consulting
Target regions
Global, North America, Europe
Detection rules
9
Indicators of compromise
37

Malware and tooling in Browser-in-the-Browser Phishing Campaign Impersonates 34+

Malware and tooling: Browser-in-the-Browser (BitB) phishing kit, PeopleForce, Salesforce Marketing Cloud, Wise Agent

A phishing operation active for at least five months impersonates recruiters from 34+ well-known brands (including American Airlines, Delta, Adidas, Adobe, Netflix, McKinsey, and OpenAI) to lure marketing professionals into fake job-interview scheduling pages. Victims are routed through a nested redirect chain abusing legitimate PeopleForce, Salesforce Marketing Cloud (exct.net), and Wise Agent CRM infrastructure before landing on a page that renders a fake 'Continue with Google' browser-in-the-browser (BitB) popup to steal Google account credentials.

How Browser-in-the-Browser Phishing Campaign Impersonates 34+ works

This is a large-scale, brand-impersonation credential-phishing operation first publicly documented by Will Thomas (Senior Threat Intelligence Advisor, Team Cymru) and reported by BleepingComputer on 2026-07-06. The operation has been active for at least five months and targets marketing professionals by impersonating recruiters at 34+ recognizable global brands spanning airlines/travel (American Airlines, Delta Air Lines, United Airlines, Booking.com), food & beverage (Coca-Cola, PepsiCo, Red Bull), apparel/luxury (Adidas, Louis Vuitton, Sephora, Levi's), technology/staffing/consulting (Adobe, Aquent, ManpowerGroup, McKinsey & Company, OpenAI), hospitality/marketing (Marriott, Omnicom Group), and entertainment/sports (FIFA, Netflix).

Exploit-chain analysis: the lure begins with an email or calendar-style invitation posing as a job-interview scheduling request from a named, real employee at the impersonated brand (using genuine names and photos to build credibility). The initial link routes through PeopleForce, a legitimate HR/recruiting SaaS platform, whose links are abused to add an air of legitimacy and to launder the URL's reputation past link-reputation and secure-email-gateway scanners. From PeopleForce the victim is redirected a second time through exct.net, the tracking-link domain of Salesforce Marketing Cloud (formerly ExactTarget) — a widely-trusted, high-reputation SaaS domain frequently allow-listed by corporate mail filters, making it an attractive redirect hop for phishing-link laundering (a pattern independently documented by Okta Threat Intelligence and Sublime Security in adjacent recruiter-phishing campaigns using the same cl.sNN.exct.net tracking-link format). A third hop passes through wiseagent.com, a real-estate CRM platform, before finally landing on the attacker-controlled page (e.g. adidas-hiring[.]com for the Adidas lure, with equivalent '<brand>-hiring'-style domains for other impersonated brands).

The landing page itself does not use a real pop-up browser window. Instead it renders a Browser-in-the-Browser (BitB) fake authentication window entirely with HTML and CSS embedded in the phishing page — recreating a convincing fake browser chrome (address bar, padlock icon, and a 'Continue with Google' OAuth-style consent screen) that never actually opens a second browser process. This nested-iframe/CSS technique traces back to the BitB concept popularized publicly by security researcher mr.d0x in 2022 and has since been adopted broadly across the recruiter-phishing ecosystem (e.g. Push Security's Calendly-brand impersonation cluster and Okta's Meta-recruiter BitB cluster use the same fundamental rendering trick against Google/Facebook login flows). Because the fake window is rendered client-side, it defeats casual visual inspection and works even though the address bar shown to the victim is entirely fabricated. Victims who submit credentials into the fake Google form have their Google account credentials harvested directly by the attacker's backend.

No CVE or software vulnerability underlies this operation — it is a pure social-engineering and legitimate-infrastructure-abuse campaign ('living off trusted SaaS services') rather than an exploit against a coded flaw. The abused platforms (PeopleForce, Salesforce Marketing Cloud, Wise Agent) are not themselves compromised or vulnerable; their legitimate link/redirect and tracking functionality is being repurposed by the threat actor to build a chain of trust that defeats URL-reputation-based defenses. The operation remains unattributed to a named threat-actor group at time of reporting and is best classified as opportunistic/financially-motivated cybercriminal activity targeting Google Workspace/Gmail accounts held by marketing and advertising staff, whose accounts are valuable for downstream business email compromise, ad-account takeover, or resale.

This specific PeopleForce/exct.net/wiseagent.com chain sits within a much longer-running, well-documented lineage of recruiter-themed brand-impersonation phishing that CTI vendors have tracked since at least September 2025. Cyberpress reported a 'Fake Google Careers Recruiters' Gmail credential-theft wave (hosted at apply.grecruitingwise.com) active since September 2025; Sublime Security's Brandon Murphy published an Attack Spotlight on an actively-evolving Google Careers impersonation scam on 2025-10-14 (amplified by CSOonline on 2025-10-22); Push Security then documented a 75+-brand Calendly-themed cluster on 2025-12-02 (covered by BleepingComputer on 2025-12-04) using the same Browser-in-the-Browser technique against Google and Facebook logins, alongside a concurrent malvertising campaign hijacking Google Ads Manager accounts. Sublime Security published an expanded follow-up on the endless lure variation on 2026-03-30, and Okta Threat Intelligence catalogued multiple concurrent recruiter-phishing campaigns sharing this infrastructure-abuse pattern in an advisory on 2026-04-30 -- shortly before Team Cymru's Will Thomas documented the specific PeopleForce/exct.net/wiseagent.com chain analyzed here. This chronology indicates a persistent, multi-vendor-tracked recruiter-phishing ecosystem rather than an isolated incident, with this campaign representing the latest and most infrastructure-diverse iteration.

MITRE ATT&CK techniques used in TL-2026-1139

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location

Credential Access

T1056.003 Web Portal Capture

Persistence

T1078.004 Cloud Accounts

Command and Control

T1090.002 External Proxy; T1102 Web Service

Collection

T1114.002 Remote Email Collection

Execution

T1204.001 Malicious Link

Initial Access

T1566.002 Spearphishing Link

Resource Development

T1583.001 Domains; T1584.006 Web Services; T1585.002 Email Accounts; T1608.005 Link Target

Reconnaissance

T1589.002 Email Addresses; T1591.004 Identify Roles

stealth

T1684.001 Impersonation

Affected products and versions in Browser-in-the-Browser Phishing Campaign Impersonates 34+

  • PeopleForce — PeopleForce HR/Recruiting SaaS Platform
    Vulnerable versions: N/A - abused as legitimate first-hop redirect infrastructure; no software vulnerability involved
    Fixed in: N/A
  • Salesforce — Marketing Cloud (ExactTarget / exct.net tracking links)
    Vulnerable versions: N/A - abused as legitimate second-hop redirect/tracking infrastructure; no software vulnerability involved
    Fixed in: N/A
  • Wise Agent — Wise Agent Real Estate CRM
    Vulnerable versions: N/A - abused as legitimate third-hop redirect infrastructure; no software vulnerability involved
    Fixed in: N/A
  • Google — Google Account / Google Workspace Sign-In (OAuth 'Continue with Google' flow)
    Vulnerable versions: Web-based Sign in with Google flow spoofed client-side via HTML/CSS Browser-in-the-Browser popup; not a Google product vulnerability
    Fixed in: N/A - social-engineering technique, mitigated via phishing-resistant MFA rather than a patch

Remediation for Browser-in-the-Browser Phishing Campaign Impersonates 34+

Immediate actions

  • Block/monitor known malicious landing domains (e.g. adidas-hiring.com and equivalent '<brand>-hiring'-style lookalike domains for other impersonated brands) at the email gateway and web proxy
  • Alert marketing, advertising, and HR-adjacent staff to scrutinize unsolicited 'schedule your interview' calendar-style invitations, especially links routed through peopleforce.io, exct.net, or wiseagent.com
  • Enforce phishing-resistant MFA (FIDO2/WebAuthn security keys or passkeys) on Google Workspace/Gmail accounts to defeat credential-only BitB capture
  • Review outbound web-proxy/link-click telemetry for nested redirect chains traversing PeopleForce -> exct.net -> wiseagent.com

Workarounds

  • Disable or restrict reliance on third-party OAuth pop-up sign-in flows in favor of full-page redirect-based Google sign-in where feasible
  • Deploy browser isolation or EDR browser-extension controls that flag full-screen/kiosk-mode simulated browser windows embedded within a webpage

Longer-term hardening

  • Deploy browser-based anti-BitB detection (DOM/CSS heuristics that flag full-screen or iframe-rendered fake browser chrome lacking a real OS window/address bar)
  • Migrate marketing/advertising staff Google Workspace accounts to FIDO2 security keys or passkeys as the primary sign-in factor
  • Implement brand-protection and DNS/URL-categorization monitoring for lookalike recruiting domains impersonating your organization
  • Train marketing, advertising, and HR-adjacent employees to verify recruiter outreach directly via the official corporate careers site rather than emailed/calendar scheduling links
  • Establish a vendor risk process for reviewing how trusted SaaS redirect/tracking domains (e.g. exct.net) are treated by secure email gateway allow-lists, since high-reputation SaaS domains are being deliberately abused as reputation-laundering hops

Timeline of Browser-in-the-Browser Phishing Campaign Impersonates 34+

  • Cyberpress reports a related, earlier wave of 'Fake Google Careers Recruiters' phishing active since September 2025, hosted at apply.grecruitingwise.com, using recruiter impersonation and Gmail credential harvesting -- documenting the broader tradecraft family this campaign belongs to, tracked as separate infrastructure from the PeopleForce/exct.net/wiseagent.com chain.
  • Sublime Security publishes an Attack Spotlight report (authored by Brandon Murphy) documenting an actively-evolving Google Careers impersonation credential-phishing scam with wide lure variation, an early precursor to the recruiter-lure/BitB tradecraft used in this campaign.
  • CSOonline reports on the Google 'Careers' scam landing job seekers in credential traps, amplifying Sublime Security's findings on the broader recruiter-phishing campaign family.
  • Push Security publishes 'Uncovering a Calendly-themed phishing campaign,' identifying 75+ impersonated brands and 31+ unique URLs using Browser-in-the-Browser kits to steal Google and Facebook credentials via fake meeting-scheduler lures, plus a concurrent malvertising campaign hijacking Google Ads Manager accounts -- the same general tradecraft family this campaign belongs to.
  • BleepingComputer reports on Push Security's Calendly-themed brand-impersonation findings ('Fake Calendly invites spoof top brands to hijack ad manager accounts'), sharing the recruiter-lure and brand-impersonation tradecraft used in this campaign.
  • Estimated start of this specific campaign's activity (the PeopleForce -> exct.net -> wiseagent.com chain), based on Team Cymru's finding that the operation had been running for at least five months prior to public disclosure on 2026-07-06.
  • Sublime Security publishes an expanded blog, 'Google Careers impersonation credential phishing scam with endless variation,' documenting continued evolution and near-endless lure variation within the same recruiter-phishing campaign family.
  • Okta Threat Intelligence publishes 'Jobseekers Exploited in Fake Recruiter Phishing Campaigns,' a threat advisory cataloging multiple concurrent recruiter-themed phishing campaigns that abuse shared lure-delivery and tracking infrastructure.
  • Campaign confirmed still active at time of public reporting, continuing to target marketing professionals at brand-impersonated companies with fake job-interview scheduling lures and the Google BitB credential harvester.
  • BleepingComputer publishes 'Phishing poses as big brand job interview to steal Google accounts,' making the campaign's TTPs and abused redirect infrastructure public to defenders.
  • Will Thomas, Senior Threat Intelligence Advisor at Team Cymru, documents the PeopleForce -> exct.net -> wiseagent.com nested redirect chain and catalogs 34+ impersonated brands used as job-interview lures, publishing supporting analysis.

Sources cited for Browser-in-the-Browser Phishing Campaign Impersonates 34+

Threats related to Browser-in-the-Browser Phishing Campaign Impersonates 34+

Detection coverage for TL-2026-1139

As of 2026-07-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1139 across Splunk SPL, Microsoft KQL and Sigma, covering 37 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-1139

2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats