Saturday, September 12, 2026

Red Bull-Themed Phishing Attacks Target Job Seekers’ Credentials

A few significant investments in email filtering, authentication procedures, and endpoint protection, attackers are constantly improving their techniques to circumvent automated security measures in a time when phishing is still a major cyberthreat.

A recent campaign identified by Evalian’s Security Operations Center (SOC) exemplifies this evolution, employing sophisticated deception to target job seekers with spoofed Red Bull recruitment emails.

These attacks leverage legitimate email services, transient VPS infrastructure, and brand impersonation to deliver malicious payloads that slip past SPF, DKIM, and DMARC checks, ultimately funneling victims to credential-harvesting sites mimicking Facebook logins.

Evolving Tactics Bypass Enterprise Defenses

By dissecting the attack’s anatomy from email headers to TLS fingerprints analysts uncovered a broader network of interconnected domains and IPs, enabling proactive detection rollouts across managed SOC clients.

Phishing Attacks
email header 

This human-led threat hunting, augmented by OSINT, transforms isolated incidents into scalable defenses, highlighting the limitations of purely automated tools in countering adaptive adversaries.

The phishing emails, masquerading as Red Bull job opportunities, originate from seemingly legitimate domains like [email protected], authenticated via Mailgun’s high-reputation IP pools.

Headers reveal sender IPs such as 198.244.57.62, with low Spam Confidence Levels (SCL=1) from Microsoft filters, allowing clean inbox delivery.

However, anomalies like the Reply-To address [email protected] expose the ruse, pointing to obfuscated infrastructure hosted on abuse-prone providers.

Embedded links direct users to domains like redbull-social-media-manager.apply-to-get-hired.com, which present a multi-stage lure: a reCAPTCHA challenge to deter scanners, a Glassdoor-esque job posting, and a fraudulent Facebook login page.

Phishing Attacks
reCAPTCHA screen

Network analysis via browser DevTools shows POST requests to /login_job endpoints resolving to IPs like 38.114.120.167, served by nginx/1.24.0 on Ubuntu, often resulting in 504 Gateway Timeouts potentially intentional stalling tactics or signs of overburdened backends in disposable phishing kits.

Infrastructure Analysis Reveals Campaign Scale

Pivoting from the phishing domain’s TLS certificate (CN=bot2shimeta.charliechaplin7eont.space, issued by Let’s Encrypt) yields critical insights through JARM fingerprinting (27d40d40d00040d00042d43d000000d2e61cae37a985f75ecafb81b33ca523).

Shodan queries combining this fingerprint with issuer details and ASN 63023 (AS-GLOBALTELEHOST) narrow down to clusters of suspicious hosts, including subdomains like mrbeastmeta.charliechaplin7eont.space and samkymeta.charliechaplin7eont.space, all resolving to the same IP and spoofing brands like MrBeast and Meta.

Passive DNS reconnaissance via VirusTotal graphs related domains such as redbull-jobs.jobapply-careers.com, indicating a templated phishing operation deployed rapidly post-domain registration (e.g., charliechaplin7eont.space created May 30, 2025, via Porkbun registrar).

The Reply-To domain user0212-stripe.com, hosted on 172.81.134.78 under DataWagon LLC, features static HTML fronts mimicking benign tech sites, but shares fingerprints with other low-detection subdomains, suggesting automated kit rentals for scalable attacks.

This campaign abuses trusted services like Mailgun and Let’s Encrypt to piggyback on reputable authentication, bypassing filters while exploiting user trust in branded lures.

According to the Report, Evalian’s SOC engineered detections mapping MITRE ATT&CK techniques like T1566.002 (Spearphishing Link) and T1071.001 (Web Protocols), correlating email IOCs with endpoint and network logs to hunt user interactions.

Queries target suspicious sender patterns, malicious URLs, and infrastructure traits, deployed fleet-wide to preempt variants.

Such operations underscore phishing’s shift toward infrastructure-as-a-service models, where attackers churn domains, leverage influencer impersonation, and introduce latencies to evade sandboxes.

For defenders, this demands layered hunting monitoring cloud mailers, TLS artifacts, and OSINT pivots beyond basic blocks, as authentication alone proves insufficient against weaponized trust.

Indicators of Compromise (IOCs)

TypeValue
Domaincharliechaplin7eont[.]space
Domain*.apply-to-get-hired[.]com
Domainuser0212-stripe[.]com
IP Address38.114.120[.]167
ASN63023 (AS-GLOBALTELEHOST)
TLS Cert CNbot2shimeta.charliechaplin7eont.space
JARM Fingerprint27d40d40d00040d00042d43d000000d2e61cae37a985f75ecafb81b33ca523
Mail Sender[email protected][.]com
Reply-To[email protected][.]com

Stay Updated on Daily Cybersecurity News. Follow us on Google News, LinkedIn, and X.

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data

Threat actors are increasingly using Claude-based AI workflows to...

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google...

New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets

A newly identified phishing campaign is abusing the legitimate...

CISA Warns of Critical GitLab Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Related Articles

Recent News