
NordVPN’s Threat Intelligence research team has identified a phishing campaign that impersonates recruiters from more than 75 global brands to harvest corporate Google Workspace and Facebook Business credentials. The operation deliberately targets marketing and communications professionals rather than finance or IT staff.
A compromised marketing professional's account typically controls Google and Facebook Ads Manager profiles, often with a payment method attached. It also gives access to corporate CMS systems, customer lists, and social media profiles with large follower counts. For attackers, this means immediate monetization. They can burn advertising budgets on malvertising campaigns served from a verified business account, or simply resell the access to other criminals.
Victims are contacted by a fake recruiter, often using the real name and photo of an actual HR employee, and invited to schedule an interview via a page that looks identical to Calendly. During the “booking” process, the victim is prompted to “Sign in with Google.”
“The scam is particularly dangerous because it targets a person's professional credibility to gain a foothold in their company,” says Adrianus Warmenhoven, cybersecurity advisor at NordVPN. “The attacker orchestrates a login through a fake window that looks so real the victim never suspects they might be handing over the keys to their company’s internal systems.”
Browser-in-the-Browser Trap
The campaign’s success relies on a technique known as browser-in-the-browser (BitB). When a victim clicks a login button, the phishing kit generates an HTML drawing that perfectly imitates a separate browser window. This includes a fake address bar with a security padlock and the correct URL, such as accounts.google.com.
Because the victim believes they are interacting with a genuine prompt, they enter their credentials and approve two-factor authentication (MFA) codes. The attackers relay these codes to the real platforms in real time, allowing them to bypass security measures and obtain a fully authenticated session.
The research team found that this is a structured, professional operation rather than a one-off scam, using hundreds of domains in continuous rotation. The hackers rely on a technique that passes their phishing links through multiple legitimate SaaS platforms in sequence. By bouncing through an HR scheduling tool, an email marketing platform, and a CRM platform, they can defeat web filters that only evaluate the first link in a message.
NordVPN analysts also discovered that the phishing kit itself was likely built with AI assistance, given the unusually descriptive inline comments and emojis found in the source code. The campaign has been seen impersonating a wide range of organizations, including:
- Tech and software: Nvidia, Adobe, Salesforce, and SoundCloud.
- Retail and apparel: Nike, Adidas, Louis Vuitton, Levi’s, and Sephora.
- Entertainment and gaming: Disney, Epic Games, and Ubisoft.
- Food and beverage: Coca-Cola, Starbucks, Heineken, and Red Bull.
- Travel and hospitality: Booking.com, Marriott, and Expedia.
- Airlines: American Airlines, Delta Air Lines, Emirates, and United Airlines.
- Sports and luxury: FIFA, Formula 1, UEFA Champions League, and Lamborghini.






















