CTM360가 브라우저 내 브라우저 기법을 이용한 채용 피싱 캠페인을 밝혀냈습니다.
CTM360가 전 세계에서 발생하는 대규모 채용 테마 피싱 캠페인을 발견했습니다. 이 캠페인은 가짜 면접 일정 페이지와 브라우저 내 브라우저(BitB) 창을 사용하여 구글과 페이스북 자격증명을 탈취하고, 고급 사례에서는 다중 인증(MFA) 요청을 실시간으로 중계합니다. 해당 내용은 RecruitTrap이라는 보고서에서 자세히 설명됩니다.
CTM360 uncovers a large-scale recruitment phishing campaign using Browser-in-the-Browser techniques.
CTM360 has revealed a large-scale global recruitment-themed phishing campaign. This campaign uses fake interview scheduling pages and Browser-in-the-Browser (BitB) windows to steal Google and Facebook credentials, with more advanced cases relaying multi-factor authentication (MFA) prompts in real time. The findings are detailed in a report titled RecruitTrap.