Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Red Bull-Themed Phishing Attacks Steal Job Seekers Login Credentials

Posted on July 15, 2025July 15, 2025 By CWS

A brand new wave of phishing emails promising a “Social Media Supervisor” place at Crimson Bull has surfaced in company and private inboxes worldwide.

Disguised as customized invites, the messages originate from [email protected] and sail by way of SPF, DKIM and DMARC checks, giving conventional filters little purpose to mistrust them.

Faux e-mail (Supply – Evalian)

Their lure capitalizes on pandemic-driven remote-work appetites and the energy-drink large’s robust model recognition.

Recipients who click on the embedded hyperlink are funnelled to a reCAPTCHA gate after which to a sophisticated Glassdoor-style emptiness web page.

Glassdoor-style pretend job description (Supply – Evalian)

Evalian analysts famous that, whereas the façade appears to be like benign, the area redbull-social-media-manager.apply-to-get-hired.com is barely weeks previous and resolves to a VPS in AS-63023, a community infamous for short-lived malicious infrastructure.

After the fake job description, victims are redirected to a counterfeit Fb login the place credentials are siphoned through a POST to /login_job on 38.114.120.167.

These credentials by no means attain Fb; as a substitute they disappear right into a backend that always returns a 504 Gateway Timeout, a stalling manoeuvre that frustrates sandboxes and masks profitable exfiltration.

Evalian researchers recognized the identical TLS JARM fingerprint throughout sibling domains spoofing MrBeast and Meta, proving the marketing campaign is a rentable equipment quite than a lone one-off.

Detection evasion is the place the operation actually shines. The attackers abuse Mailgun’s high-reputation IP pool, letting them inherit Xero’s belief halo whereas hiding the true reply-to deal with [email protected].

They automate Let’s Encrypt issuance so each host presents a contemporary, legitimate certificates, erasing typical “self-signed” purple flags. Even the reCAPTCHA isn’t for the person; it throttles URL-scanning bots lengthy sufficient to drop them.

the place mail.sender_domain==”publish.xero.com”
and mail.reply_to matches “.*user0212-stripe.com”
and url.area endswith(“apply-to-get-hired.com”)
and community.jarm==”27d40d40d00040d00042d43d000000d2e61cae37a985f75ecafb81b33ca523″

The Kusto-style question above, tailored from Evalian’s SOC guidelines, triangulates sender fame, anomalous reply-to domains, malicious top-level infrastructure and the shared JARM signature, delivering high-fidelity alerts with out drowning analysts in noise.

Whereas job hunters stay the prime targets, organizations ought to block the listed IOCs, monitor outbound visitors for 38.114.120.167, and educate customers that even emails passing each authentication check should still be a wolf in well-forged clothes.

Examine dwell malware conduct, hint each step of an assault, and make sooner, smarter safety selections -> Strive ANY.RUN now

Cyber Security News Tags:Attacks, BullThemed, Credentials, Job, Login, Phishing, Red, Seekers, Steal

Post navigation

Previous Post: Sesame Workshop Regains Control of Elmo’s Hacked X Account After Racist Posts
Next Post: MITRE Unveils AADAPT Framework to Tackle Cryptocurrency Threats 

Related Posts

Sophisticated Skitnet Malware Actively Adopted by Ransomware Gangs to Streamline Operations Cyber Security News
New ToneShell Backdoor With New Features Leverage Task Scheduler COM Service for Persistence Cyber Security News
New Android Malware GhostSpy Let Attacker Take Full Control Over Infected Devices Cyber Security News
New DroidLock Malware Locks Android Devices and Demands a Ransom Cyber Security News
Supply Chain Security Mitigating Third-Party Risks Cyber Security News
New ‘SleepyDuck’ Malware in Open VSX Marketplace Allow Attackers to Control Windows Systems Remotely Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • IoT Security Firm Exein Raises €100 Million
  • Phantom Stealer Attacking Users to Steal Sensitive Data like Passwords, Browser Cookies, Credit Card Data
  • SonicWall Patches Exploited SMA 1000 Zero-Day
  • Kimsuky Spreads DocSwap Android Malware via QR Phishing Posing as Delivery App
  • China-Linked Hackers Exploiting Zero-Day in Cisco Security Gear

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • IoT Security Firm Exein Raises €100 Million
  • Phantom Stealer Attacking Users to Steal Sensitive Data like Passwords, Browser Cookies, Credit Card Data
  • SonicWall Patches Exploited SMA 1000 Zero-Day
  • Kimsuky Spreads DocSwap Android Malware via QR Phishing Posing as Delivery App
  • China-Linked Hackers Exploiting Zero-Day in Cisco Security Gear

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2025 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark