Threat reportPhishingTL-2026-2395

Operation Fake KickOff — Attackers Abuse Recruiters and SaaS to Harvest Corporate Google Workspace Credentials

highACTIVE

Operation Fake KickOff (TL-2026-2395), also tracked as Operation Fake KickOff, is a high-severity phishing campaign, first published 2026-07-15 and last reviewed 2026-10-02. It is attributed to O-UNC-038 with medium confidence, affects Google Google Workspace, maps to 13 MITRE ATT&CK techniques (T1036.005, T1056.001, T1071.001), and is covered by 9 detection rules and 30 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
13MITRE ATT&CK
Actors
1O-UNC-038
Detection rules
9SPL · KQL · Sigma
IOCs
30Indicators of compromise

Key facts for TL-2026-2395

Threat ID
TL-2026-2395
Also known as
Operation Fake KickOff, O-UNC-038 Campaign, Fake Recruiter Phishing Campaign, FIFA World Cup Recruiter Phishing
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
Last reviewed
Attribution
O-UNC-038
Attribution confidence
MEDIUM
Motivation
UNKNOWN
Target sectors
consulting, technology, airlines, hospitality, entertainment, apparel, food-and-beverage, management-consulting, staffing, marketing-advertising, retail, luxury-goods
Target regions
North America, Europe, Middle East
Detection rules
9
Indicators of compromise
30
Updates
2026-10-02

Malware and tooling in Operation Fake KickOff

Malware and tooling: React AitM Phishing Kit

How Operation Fake KickOff works

A sustained, multi-stage Adversary-in-the-Middle (AitM) phishing campaign (O-UNC-038) active since April 2025 that abuses legitimate SaaS platforms to deliver recruiter-themed lures impersonating 50+ global brands across 15 industry verticals. Uses a React-based Browser-in-the-Box (BitB) phishing kit to bypass MFA and harvest Google Workspace credentials and live session tokens via 232 dedicated phishing domains and 80 C2 servers hosted on Render, with data exfiltrated downstream to Telegram bots.

Operation Fake KickOff is an ongoing, multi-stage corporate credential-theft campaign tracked by Intel 471 and Okta as cluster O-UNC-038. Active since at least April 2025, the operation systematically abuses legitimate enterprise SaaS platforms — including PeopleForce (HRM/ATS), Salesforce Marketing Cloud / ExactTarget, SendGrid, and Zoho — to deliver recruiter-themed phishing emails to marketing, HR, and business professionals. The emails impersonate real recruiters at over 50 well-known global brands, with names and profile pictures likely sourced from LinkedIn reconnaissance. The campaign's most targeted sector is HR consulting (approximately 54% of observed phishing infrastructure), with Robert Half Inc. and Aquent LLC accounting for roughly 50% of impersonated brand domains.

The attack chain employs a nested redirect architecture designed for reputation laundering: an email sent through PeopleForce inherits the platform's trusted domain reputation, bypassing SPF/DKIM/DMARC and Secure Email Gateway filters. The embedded link routes through Salesforce Marketing Cloud (exct.net) for click tracking, then through Wise Agent (a legitimate real estate CRM), before landing on a Netlify-hosted phishing page. Each hop uses a legitimate platform, making the chain difficult to block by reputation alone and easy to rotate.

Upon arrival, victims see a realistic Calendly-style interview scheduling interface. The page blocks personal email providers (Gmail, Yahoo, MSN, iCloud, Outlook, Hotmail, ProtonMail, AOL) by presenting a validation error, forcing entry of a corporate email address. Once a valid corporate email is submitted, the page launches a Browser-in-the-Box (BitB) attack — an HTML/CSS-rendered replica of a Google sign-in popup contained entirely within the current browser tab (not a real OS window), first documented by researcher mrd0x in 2022. The fake window displays a legitimate-looking URL bar showing accounts.google.com, making it indistinguishable to most users.

The React-based phishing kit delivers real-time credential interception with a 3-second setInterval polling loop to /check_response?session_id=, maintaining a live feedback loop with the attacker's control panel on Render cloud hosting. It includes four dynamically-routed MFA interception scripts: /email (spoofed Google two-step prompt for email-delivered codes), /2fa (TOTP prompt for Google Authenticator codes), /sms (SMS confirmation code prompt), and /tap (a high-fidelity Google Prompt notification simulation polling at 500ms intervals to retrieve a verification number from the attacker). Upon successful session hijacking, victims are redirected to a legitimate Google Calendar workspace entry or external URL.

The campaign infrastructure is substantial: 232 typosquatted phishing domains (.com TLD dominant), 80 C2 servers hosted on Render Cloud (*.onrender.com), and hosting via Amazon CloudFront and EC2. Domains were primarily registered through Hosting Concepts BV, Trustname.com, Name.com, Nicenic International Group Co. Ltd., and Key-Systems GmbH. Victim telemetry (IP address, geolocation) is collected via the third-party ipwho.is service. Stolen credentials and session tokens are transmitted via HTTP POST to C2 servers and exfiltrated downstream to Telegram bots.

Intel 471 noted that the phishing kit code exhibited "unusually descriptive, verbose inline comments, the inclusion of emojis and overall programmatic neatness" — indicators that generative AI tools assisted in its development. The operation recently pivoted to exploit FIFA World Cup 2026 visibility (with the domain fifahr-careers.com serving as the initial investigation entry point), but researchers assess that impersonated brands are "highly unlikely to be the ultimate targets" — instead serving as a mechanism to harvest corporate access from secondary target organizations, suppliers, or industry competitors by exploiting the psychology of job seekers wanting roles at premier brands. The campaign has demonstrated sustained operational capability with continuously cycling thematic definitions and infrastructure since early 2025.

MITRE ATT&CK techniques used in TL-2026-2395

Defense Evasion

T1036.005 Match Legitimate Resource Name or Location

Credential Access

T1056.001 Keylogging; T1111 Multi-Factor Authentication Interception; T1539 Steal Web Session Cookie

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1102.002 Web Service: Bidirectional Communication

Execution

T1204.001 User Execution: Malicious Link

lateral-movement

T1550.004 Use Alternate Authentication Material: Web Session Cookie

Initial Access

T1566.002 Phishing: Spearphishing Link

Resource Development

T1583.001 Acquire Infrastructure: Domains; T1584.004 Compromise Infrastructure: Server; T1587.001 Develop Capabilities: Malware

reconnaissance

T1592.004 Client Configurations

Affected products and versions in Operation Fake KickOff

  • Google — Google Workspace
    Vulnerable versions: All versions (no CVE — credential theft via social engineering)
  • PeopleForce — HRM & ATS Platform
    Vulnerable versions: Platform abused as email delivery vector
  • Salesforce — Marketing Cloud (ExactTarget)
    Vulnerable versions: Platform abused for redirect chain and click tracking
  • SendGrid — Email Delivery Service
    Vulnerable versions: Platform abused for email delivery
  • Zoho — Zoho Campaigns / Email Platform
    Vulnerable versions: Platform abused for email delivery
  • Wise Agent — Real Estate CRM
    Vulnerable versions: Platform abused as redirect hop
  • Netlify — Netlify Hosting
    Vulnerable versions: Platform abused to host phishing landing pages (aquent-careers.netlify.app)
  • Render — Render Cloud Hosting
    Vulnerable versions: Platform hosted 80 C2 servers (*.onrender.com) used for credential/session exfiltration

Remediation for Operation Fake KickOff

Immediate actions

  • Block network connections to *.onrender.com domains unless business-justified
  • Block newly registered domains matching [brand]-{careers|jobs|hiring|recruiting|hr} and {jobsat|careers|talent}-[brand] naming patterns
  • Deploy Sigma rules detecting DNS queries and network connections to Render Cloud infrastructure
  • Scan email gateway logs for nested redirect chains through PeopleForce, ExactTarget, and Wise Agent to typosquatted domains
  • Report abuse to Salesforce Platform Abuse team for ExactTarget/Salesforce Marketing Cloud account takedown

Workarounds

  • Train HR/talent acquisition teams to monitor for LinkedIn impersonation of their recruiter profiles
  • Train users to verify browser pop-ups: a legitimate browser login window can be dragged outside the browser frame — if trapped inside the page borders, it is a BitB replica
  • Advise job applicants to use official careers portals rather than email links soliciting interview scheduling
  • Implement email banner warnings on all externally-sourced recruitment-related messages

Longer-term hardening

  • Deploy phishing-resistant MFA (FIDO2 WebAuthn / passkeys / Titan Security Keys) and disable SMS and voice MFA
  • Implement behavioral URL analysis in web gateways that inspects the full redirect chain, not just the first hop
  • Monitor DMARC/DKIM/SPF enforcement and alert on recruitment-themed emails from unfamiliar domains
  • Regularly scan for typosquatted domains registered against your brand and pursue takedown actions
  • Integrate Intel 471 Titan API or CraftedSignal feeds for continuous IOC ingestion
  • Enable password managers — they refuse to autofill on unexpected domains, providing an additional detection layer

Timeline of Operation Fake KickOff

  • Operation Fake KickOff begins — first observed recruiter-themed phishing emails using Outlook addresses bearing impersonated company names target marketing and HR professionals
  • Campaign expands significantly — 141 unique typosquatted phishing domains become active, campaign shifts from Outlook impersonation to registered domains with systematic naming conventions ([brand]-careers.com, [brand]-jobs.com, etc.)
  • Okta Threat Intelligence publishes analysis of O-UNC-038 cluster documenting 400+ phishing domains across two sub-campaigns: a BitB campaign targeting Facebook credentials (143 domains) and a Google Workspace credential theft campaign (84+ domains), both using Salesforce ExactTarget for redirect chains and Telegram for data exfiltration
  • Campaign pivots to exploit FIFA World Cup 2026 visibility — registers fifahr-careers.com and related domains (fifaworldcup-jobs.com, fifa-careerportal.com, fifa-careerhub.com, fifa-talenthub.com) targeting job seekers interested in FIFA positions
  • Will Thomas (Team Cymru senior threat advisor) publishes GitHub gist documenting 34+ phishing domains across 15 brand verticals and detailing the nested redirect chain: PeopleForce → Salesforce ExactTarget (exct.net) → Wise Agent (wiseagent.com) → Netlify-hosted BitB phishing page
  • BleepingComputer publishes technical article naming the impersonated brands (Adidas, Coca-Cola, Delta Air Lines, Netflix, OpenAI, Louis Vuitton, FIFA, and 30+ others) and highlighting the BitB technique for Google account credential theft, specifically citing Adidas recruiter Paulina Manzo's LinkedIn identity theft
  • Intel 471 publishes comprehensive 'Operation Fake KickOff' report documenting full campaign scale: 232 phishing domains, 80 C2 servers on Render cloud, React-based AitM phishing kit with AI-assisted development indicators, four MFA-interception components, and the complete technical analysis of the attack chain

Update history for TL-2026-2395

  • 2026-10-02 — tweetfeed.live community intel: New TL_OSINT_Scan community intel: 1 newly-corroborated indicator(s), 5 community-related indicator(s).

Sources cited for Operation Fake KickOff

Detection coverage for TL-2026-2395

As of 2026-10-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2395 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
30 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-2395

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats