Operation Fake KickOff: Recruiter-Impersonation AitM/BitB Toolkit Abuses Salesforce, SendGrid, Zoho and Render to Harvest Google Workspace Credentials and Bypass MFA — Threadlinqs Intelligence
As of 2026-07-15, Operation Fake KickOff: Recruiter-Impersonation AitM/BitB Toolkit Abuses Salesforce, SendGrid, Zoho and Render to Harvest Google Workspace Credentials and Bypass MFA is a high-severity phishing threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-1388 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
A multi-stage phishing operation, tracked by Intel 471 as overlapping Okta's O-UNC-038 cluster, impersonates recruiters from 52+ global brands to lure marketing and HR professionals to fake
Operation Fake KickOff is an ongoing, financially-motivated credential-harvesting campaign first tracked by Intel 471 and active since at least April 2025 (cluster registration activity from June 5, 2025), with a FIFA World Cup 2026-themed pivot detected June 24, 2026 and public disclosure via BleepingComputer on July 6, 2026. The operation systematically abuses legitimate SaaS sales, marketing and cloud infrastructure -- Salesforce Marketing Cloud/ExactTarget (exct.net), SendGrid, Zoho, the PeopleForce HR platform, and the real-estate CRM wiseagent.com -- as redirect chains to distribute recruiter-impersonation phishing emails while evading email security controls that trust these reputable domains. Emails spoof real recruiter names and photographs lifted from LinkedIn and direct marketing/HR-adjacent job seekers to typosquatted domains (e.g., fifahr-careers.com, adidas-hiring.com) hosting a Calendly-style interview-scheduling interface. Victims are prompted to authenticate via 'Continue with Google' using a corporate account, which loads a browser-in-the-browser (BitB) fake Google sign-in window -- HTML/CSS rendered inside the page rather than a real OS-level browser window, making it visually indistinguishable from a legitimate popup. The phishing kit is built on the React framework and, per Intel 471's analysis of inline code comments, emojis and structural neatness, was very likely generated with the assistance of generative-AI coding tools. Once credentials are submitted to /api/login, the phishing frontend opens a persistent 3-second polling loop against /check_response?session_id= to maintain live, bidirectional communication with an adversary-controlled backend, letting the operator view captured credentials in real time and interactively push follow-on MFA-bypass prompts to the victim's browser. Four dedicated components handle MFA interception: an /email endpoint spoofing Google's two-step email verification prompt, a /2fa endpoint requesting a Google Authenticator TOTP code, an /sms endpoint requesting an SMS confirmation code, and a /tap endpoint that simulates a high-fidelity Google Prompt push notification, polling every 500ms for an attacker-supplied verification_number and instructing the victim to approve it in the real Gmail mobile app. A hardcoded credential filter discards personal webmail domains (Google, Yahoo, MSN, iCloud, Outlook, Hotmail, ProtonMail, AOL) so only corporate Google Workspace accounts are retained. The kit also queries the third-party ipwho.is geolocation service to enrich victim telemetry (IP address, geolocation) before POSTing the full capture to /api/login. Infrastructure comprises 232 dedicated phishing domains (predominantly .com, using brand+keyword naming patterns such as -careers, -jobs, -hiring, -recruiting, -hr, -talent, -calendly, -schedulecall) registered through Hosting Concepts BV, Trustname.com, Name.com, Nicenic International Group Co. Ltd. and Key-Systems GmbH, and hosted on Amazon CloudFront/EC2 with domains also generated via the Netlify AI platform. Exfiltration and C2 rely on 80 backend instances hosted on Render's onrender.com PaaS, with stolen credentials and session data forwarded to Telegram bots for real-time operator access. The campaign spans 15 industry verticals and impersonates at least 52 organizations -- roughly 54% of infrastructure targets HR consulting, with Robert Half Inc. and Aquent LLC accounting for ~50% of observed domains alone. Broader brand impersonation documented by Team Cymru/BushidoUK and Malwarebytes includes Netflix, Coca-Cola, PepsiCo, Red Bull, Adidas, Louis Vuitton, Sephora, Levi's, Adobe, ManpowerGroup, McKinsey & Company, OpenAI, Marriott, Omnicom Group, American Airlines, Booking.com, Delta Air Lines, United Airlines and FIFA, primarily targeting marketing professionals and entry-level job seekers. Intel 471 assesses strong overlap with Okta's previously reported O-UNC-038 cluster (December 2025 advisory): both target Google Works
Weaknesses (CWE)
CWE-451, CWE-290, CWE-1021
Target sectors: humanresourcesconsulting, recruiting, marketing, technology, hospitality, airlinestravel, foodandbeverage, apparelluxuryretail, entertainmentsports, consulting, finance
Target regions: Global, North America, Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1589, T1593, T1583, T1583, T1587, T1585, T1584, T1566, T1566, T1204