# Operation Fake KickOff — Attackers Abuse Recruiters and SaaS to Harvest Corporate Google Workspace Credentials

> A sustained, multi-stage Adversary-in-the-Middle (AitM) phishing campaign (O-UNC-038) active since April 2025 that abuses legitimate SaaS platforms to deliver recruiter-themed lures impersonating 50+ global brands across 15 industry verticals. Uses a React-based Browser-in-the-Box (BitB) phishing kit to bypass MFA and harvest Google Workspace credentials and live session tokens via 232 dedicated phishing domains and 80 C2 servers hosted on Render, with data exfiltrated downstream to Telegram bots.

- **Published:** 2026-07-15T00:00:00Z
- **Last reviewed:** 2026-10-02T12:46:54Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2395
- **ID:** TL-2026-2395
- **Severity:** HIGH
- **Category:** PHISHING
- **Status:** ACTIVE
- **Actor:** O-UNC-038
- **Detections:** 9 · **IOCs:** 30 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Operation Fake KickOff is an ongoing, multi-stage corporate credential-theft campaign tracked by Intel 471 and Okta as cluster O-UNC-038. Active since at least April 2025, the operation systematically abuses legitimate enterprise SaaS platforms — including PeopleForce (HRM/ATS), Salesforce Marketing Cloud / ExactTarget, SendGrid, and Zoho — to deliver recruiter-themed phishing emails to marketing, HR, and business professionals. The emails impersonate real recruiters at over 50 well-known global brands, with names and profile pictures likely sourced from LinkedIn reconnaissance. The campaign's most targeted sector is HR consulting (approximately 54% of observed phishing infrastructure), with Robert Half Inc. and Aquent LLC accounting for roughly 50% of impersonated brand domains.

The attack chain employs a nested redirect architecture designed for reputation laundering: an email sent through PeopleForce inherits the platform's trusted domain reputation, bypassing SPF/DKIM/DMARC and Secure Email Gateway filters. The embedded link routes through Salesforce Marketing Cloud (exct.net) for click tracking, then through Wise Agent (a legitimate real estate CRM), before landing on a Netlify-hosted phishing page. Each hop uses a legitimate platform, making the chain difficult to block by reputation alone and easy to rotate.

Upon arrival, victims see a realistic Calendly-style interview scheduling interface. The page blocks personal email providers (Gmail, Yahoo, MSN, iCloud, Outlook, Hotmail, ProtonMail, AOL) by presenting a validation error, forcing entry of a corporate email address. Once a valid corporate email is submitted, the page launches a Browser-in-the-Box (BitB) attack — an HTML/CSS-rendered replica of a Google sign-in popup contained entirely within the current browser tab (not a real OS window), first documented by researcher mrd0x in 2022. The fake window displays a legitimate-looking URL bar showing accounts.google.com, making it indistinguishable to most users.

The React-based phishing kit delivers real-time credential interception with a 3-second setInterval polling loop to /check_response?session_id=, maintaining a live feedback loop with the attacker's control panel on Render cloud hosting. It includes four dynamically-routed MFA interception scripts: /email (spoofed Google two-step prompt for email-delivered codes), /2fa (TOTP prompt for Google Authenticator codes), /sms (SMS confirmation code prompt), and /tap (a high-fidelity Google Prompt notification simulation polling at 500ms intervals to retrieve a verification number from the attacker). Upon successful session hijacking, victims are redirected to a legitimate Google Calendar workspace entry or external URL.

The campaign infrastructure is substantial: 232 typosquatted phishing domains (.com TLD dominant), 80 C2 servers hosted on Render Cloud (*.onrender.com), and hosting via Amazon CloudFront and EC2. Domains were primarily registered through Hosting Concepts BV, Trustname.com, Name.com, Nicenic International Group Co. Ltd., and Key-Systems GmbH. Victim telemetry (IP address, geolocation) is collected via the third-party ipwho.is service. Stolen credentials and session tokens are transmitted via HTTP POST to C2 servers and exfiltrated downstream to Telegram bots.

Intel 471 noted that the phishing kit code exhibited "unusually descriptive, verbose inline comments, the inclusion of emojis and overall programmatic neatness" — indicators that generative AI tools assisted in its development. The operation recently pivoted to exploit FIFA World Cup 2026 visibility (with the domain fifahr-careers.com serving as the initial investigation entry point), but researchers assess that impersonated brands are "highly unlikely to be the ultimate targets" — instead serving as a mechanism to harvest corporate access from secondary target organizations, suppliers, or industry competitors by exploiting the psychology of job seekers wanting roles at premier brands. The campaign has demonstrated sustained operational capability with continuously cycling thematic definitions and infrastructure since early 2025.

## MITRE ATT&CK

- T1583.001 Acquire Infrastructure: Domains
- T1587.001 Develop Capabilities: Malware
- T1584.004 Compromise Infrastructure: Server
- T1566.002 Phishing: Spearphishing Link
- T1204.001 User Execution: Malicious Link
- T1056.001 Keylogging
- T1539 Steal Web Session Cookie
- T1111 Multi-Factor Authentication Interception
- T1036.005 Match Legitimate Resource Name or Location
- T1550.004 Use Alternate Authentication Material: Web Session Cookie
- T1592.004 Client Configurations
- T1071.001 Application Layer Protocol: Web Protocols
- T1102.002 Web Service: Bidirectional Communication

## Sources

- [Intel 471 — Operation Fake KickOff: Attackers Abuse Recruiters and SaaS to Harvest Work Credentials](https://www.intel471.com/blog/operation-fake-kickoff-attackers-abuse-recruiters-and-saas-to-harvest-work-credentials)
- [BleepingComputer — Phishing Poses as Big-Brand Job Interview to Steal Google Accounts](https://www.bleepingcomputer.com/news/security/phishing-poses-as-big-brand-job-interview-to-steal-google-accounts/)
- [Okta — Jobseekers Exploited in Fake Recruiter Phishing Campaigns (O-UNC-038)](https://www.okta.com/blog/threat-intelligence/jobseekers-exploited-in-fake-recruiter-phishing-campaigns/)
- [Will Thomas (Team Cymru) — GitHub Gist: GmailPhishingAlert with IOC domain list](https://gist.github.com/BushidoUK/57c38d5ee75481fb237e968a537de778)
- [mrd0x — Browser In The Browser (BITB) Phishing Attack](https://mrd0x.com/browser-in-the-browser-phishing-attack/)
- [CraftedSignal — Operation Fake KickOff Threat Brief with Sigma Rules](https://feed.craftedsignal.io/briefs/2026-07-operation-fake-kickoff/)
- [Dark Reading — Big-Brand Jobs Scam Targets Marketing Pros for Google Accounts](https://www.darkreading.com/cyberattacks-data-breaches/big-brand-jobs-scam-marketing-pros-google-accounts)
- [Cybersecurity News — Hackers Use Recruiter Phishing Emails and Fake Career Pages to Steal Credentials](https://cybersecuritynews.com/hackers-use-recruiter-phishing-emails-and-fake-career-pages/)
- [BushidoUK — urlscan.io Scan of Phishing Landing Page](https://urlscan.io/result/019f2485-084f-739a-bf50-3a311fd848a4/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2395
