
The newest phishing pages screen out personal email addresses. They only want the work login.
Research into a campaign called RecruitTrap describes fake recruiter messages and a sign-in page that, opened on a phone, has no address bar left to check.
On 24 August the mobile security firm Zimperium published research into a phishing campaign it calls RecruitTrap, in which attackers impersonate HR staff at well known companies and send interview-themed messages. Infosecurity Magazine covered the findings the following day. Two details are worth pulling out for any business whose staff read email on a phone, because between them they undo the advice most people have been given about spotting a fake login.
It checks whether you are worth phishing
The first is a filter. Zimperium found that the phishing kit does not process every victim, and that it actively screens what is typed in and rejects personal email domains. Enter a personal address and the attack stops. Enter a work address and it carries on. That tells you what the operation is for. The person reading about the job is not the target. The account they hold at their current employer is. Zimperium's assessment is that a compromised corporate account can yield OAuth tokens along with access to internal communications and cloud applications, which is what makes onward movement inside an organisation quick once the first login is taken.
On a phone there is nothing left to check
The second detail is that the attack changes shape depending on the device. On a desktop the victim sees a browser-in-the-browser simulation, a fake popup window drawn inside the page. On a phone there is no popup at all. The kit serves a full-screen counterfeit login page instead, and Zimperium's point is blunt: on mobile there are close to no visual indicators that separate a fake login from a real sign-in prompt, because the address bar and the rest of the browser furniture are not on screen. Every piece of phishing advice that ends with checking the address before you type your password assumes an address is visible. On a phone, at the moment it matters, it is not.
Blocklists arrive after the fact
Zimperium published 46 previously unreported indicators of compromise, and its telemetry shows how far ahead of public reporting this infrastructure runs. Recent domains went between 7 and 59 days before being flagged publicly, and one domain registered in October 2019 was not publicly flagged until January 2026. A filter that works from a list of known-bad addresses is looking backwards by design. It will catch last month's campaign and it will not catch a domain that was registered on Tuesday.
The lure works because the brands are real
The domains impersonated recognisable employers, among them Amazon, Apple, Boeing, Deloitte, Emirates Group, FIFA, Heineken, Lego and Louis Vuitton. A message that appears to come from a recruiter at a name that size, landing at a quiet moment, gets opened. It is also a lure that staff have a reason not to mention to anyone at work, and that should concern an employer more than the technology does. Somebody quietly looking at a job move is unlikely to walk over and ask a colleague whether the login page looked right.
What actually reduces the risk
Zimperium's own recommendation is mobile threat defence, which is the product it sells, so weigh that accordingly. The controls available to a smaller firm are less exotic. Multi-factor authentication is still the first one, and the stronger forms matter here: passkeys and hardware security keys are tied to the real sign-in address, so a copied page cannot complete the sign-in even when the password is typed into it. Conditional access rules in Microsoft 365 that restrict sign-ins to known devices or locations cut the value of a stolen password further. Beyond the technology, tell people plainly that a recruiter asking them to sign in with a work account to view a role is the tell, and give them somewhere to report it that does not require explaining why they were reading a job advert.
What this means for your business
Look at what the phishing kit refuses to do. It throws away personal accounts, because the value sits in the work login. Two jobs follow from that. Check where multi-factor authentication is switched on across your Microsoft 365 tenant, and check whether it can be satisfied by a code that a convincing fake page could simply ask for. Then stop leaning on the advice to check the web address, because it stops working the moment somebody opens the message on a phone, which is where most people read email now. Make reporting easy and blameless while you are at it, since the staff most likely to meet this one are the staff least likely to want to explain the context. If you want your sign-in settings reviewed against this, that is a short piece of work we can run for you.
#WEARECOBALT
Ready when you are.
Tell us what's slowing your business down. We'll tell you exactly how we'd fix it — plainly, with no obligation.