NordVPN's Threat Intelligence research unit announces that it has uncovered a sophisticated phishing campaign targeting job applicants, impersonating some of the world's most recognized companies. The operation exploits the names of global giants such as Meta (and its subsidiaries, like Facebook and WhatsApp), Disney, Coca-Cola, and Spotify to steal victims' Facebook credentials and hijack their accounts.
The investigation revealed a multi-stage operation. In it, attackers use hidden domains (“HUBs”), referral link activation mechanisms, and realistic job advertisement interfaces to guide victims through a carefully constructed path. The final step redirects them to a fake Facebook login page, designed to capture their credentials.
“Job seekers are particularly vulnerable because they are already accustomed to sharing personal information and following instructions from unknown contacts,” says Domininkas Virbickas, product director at NordVPN. “These campaigns exploit this trust using sophisticated communications and convincing fake career portals that are virtually indistinguishable from the real ones.”
The campaign begins with a cold email, usually sent through legitimate services like Google AppSheet to bypass spam filters. These messages appear polished and professional, with impeccable grammar and a tone that mimics real recruitment approaches. The contact lists are likely compiled through automated data collection from platforms like LinkedIn or obtained from previous data breaches.

The link in the email directs victims to a "HUB" domain (such as careers.meta-findyourjob[.]com). These sites are designed with a built-in evasion mechanism. If someone, whether a security analyst or an automated scanner, visits the domain directly, they will only see a generic, inert page with no interactive functionality.
Thus, the malicious content is only activated when the site is accessed through a specific referral link embedded in the phishing email. This referral link acts as a key, unlocking a clickable "Search for a job" button that would otherwise remain hidden.

As soon as the victim clicks on the link, they are redirected to an intermediary domain that simulates a legitimate job portal. The interface allows users to browse seemingly trustworthy job postings from the fake brand, reinforcing the illusion that they are participating in a real selection process.
Examples include plus.jobfusion-mt[.]com and official.professionlaunch-mt[.]com for Meta, careers.coca-contactnow[.]info for Coca-Cola, connect.spotifycareerapply[.]com for Spotify, and jobquest.wdcfuturesteps[.]com for Disney.

The trap closes when the victim clicks on “Apply” or “Submit application.” Instead of a job application form, they are redirected to a phishing page that requires them to log in via Facebook to “proceed with the application.” This page is designed to capture the victim's Facebook credentials, giving attackers complete control of the account and potentially all services linked to it.

The campaign highlights a growing trend of attackers using trusted brands and professional contexts as weapons to circumvent victims' natural skepticism. Because the phishing flow mimics a real recruitment process so precisely, even cautious users can be caught off guard.
NordVPN suggests three actions users should take when receiving any type of email with job openings:
- Verify the URL before entering any credentials. Legitimate companies host career pages on their official domains, not on third-party websites with unusual names. The same applies to login requests on social media. The “Log in with Facebook” buttons on legitimate platforms will always redirect you to the official facebook.com domain. If the login page is hosted on an unknown URL, it is likely a phishing attempt.
- Enable multi-factor authentication (MFA) on all social media accounts. Even if credentials are compromised, 2FA can prevent attackers from gaining access.
- Never trust unsolicited job offers that arrive via email or messaging apps, especially those that pressure you to act quickly.
Methodology:
The investigative process used open-source intelligence (OSINT) methodologies and the consequent need to corroborate and validate the data obtained through cross-referencing.
In particular, the core of our data collection strategy included the use of specific “dorks” (advanced search strings) applied to major generic search engines, as well as the use of specialized search engines to index domains, websites, and devices exposed on the internet. Among these specialized tools, we made extensive use of search engines for the Internet of Things (IoT) and service platforms similar to Shodan, such as Fofa.io and Shodan.io. These tools allowed us to identify not only the domains but also the exposed services and ports, revealing potential vulnerabilities or unintentional exposures.
The main objective of this layered research methodology was twofold:
- To obtain the most exhaustive and complete view possible of the landscape of the digital entities involved.
- To accurately identify the domains that have actually been compromised, going beyond simply identifying theoretically vulnerable domains.
This detailed analysis ensured that the conclusions were based on verified data and that the perimeter of the compromised systems was delineated with the greatest possible precision.



