UPDATE
Attackers are chaining together multiple Google services in order to get phishing links past security gateways.
Cybersecurity vendor KnowBe4 published research on Sept. 4 concerning an ongoing phishing campaign observed in the wild. To some extent, the mechanics of the campaign are typical: The threat actor sends a malicious email under false pretenses, the victim clicks the link, and the link leads to a malicious landing page where the victim is compromised.
What sets this campaign apart is the link in the initial phishing email. To bypass gateways, email filters, and other security tools, the link relies on a chain of redirects across Google domains, intending for link inspectors to see multiple Google domains and let the URL through.
Attackers regularly lean on redirects through legitimate infrastructure and have for years, but this method stands out because the threat campaign deliberately uses multiple Google services within the redirection chain. KnowBe4 threat analysts Prabhakaran Ravichandhiran and Jeewan Singh Jalal described a three-hop redirect chain that uses services including Google Meet, DoubleClick ad infrastructure, Google Custom Search, Google Image Search, Google Tag Manager, and Google Analytics.
“By the time a defender inspects the sending domain, the embedded link, or the intermediate hops, everything still looks clean. The harvester at the end of the chain is built to wait for that inspection to pass,” the blog post read. “Most phishing campaigns embed a malicious link and bet on the gateway missing it. This one does not need the gateway to miss anything. It feeds the gateway exactly what it expects: trusted Google domains at every hop.”
Using Google Infrastructure in Targeted Attacks
At the end of the chain, the URL redirects to a phishing landing page. In some instances, KnowBe4 observed credential harvesting from a fake corporate login page. In others, a script installs ScreenConnect as a remote access tool via a fake identity verification prompt.
Notably, once the victim clicks a phishing link, the landing page’s JavaScript dynamically constructs a credential harvesting landing page from the victim’s email address alone, displaying a live screenshot of the victim’s corporate website behind the login page. There is also a multilingual UI, which localizes the victim’s session to their location.
As far as lures go, KnowBe4 says the campaign does not adhere to one single type but rather a range of business contexts. Researchers saw document review, credential expiry, package delivery, payment notification, government benefit, and voicemail lures. Once the victim’s credentials are entered, they’re delivered to the operator’s Telegram channel within seconds, along with other information including “the victim’s IP address, geolocation, browser string and verified MX records for their organization.”
The campaign appears to be targeted rather than indiscriminate, based on how the phishing URLs are constructed. “Victim email addresses are encoded in base64 and hidden in the URL hash fragment, which browsers strip before sending any request, making it invisible to server-side logs and most URL scanners, effectively masking the pre-targeted nature of the campaign,” the blog post read.
James Dyer, head of threat intelligence at KnowBe4, tells Dark Reading that even organizations with basic protections against phishing may not be safe. For example, the compromised domains in the campaign’s phishing URLs hold good reputation, letting them slip past reputation-based filtering. Additionally, while phishing-resistant MFA is important, “It fails against this campaign’s two other paths, device-code interception and RMM delivery.”
“Neither path touches a login form, so there’s no MFA challenge to protect,” he says.
KnowBe4’s research includes indicators of compromise (IoCs) as well as recommendations to block the IoCs at the DNS filter, proxy, and SIEM level now; hunt for Telegram bot API traffic; force credential resets for users that may have received lures associated with this campaign; hunt for unauthorized ScreenConnect installations or activity; and alert users to the URL fragment technique.
“An email address in the URL after # is a signal the link is pre-targeted,” the threat analysts wrote.
Google did not respond to Dark Reading’s request for comment.
This story was updated at 2:15 p.m. ET on Sept. 9 to reflect additional comments from KnowBe4.

Comments are closed