Google Search Update Hides URLs, Increases Phishing Risk
Key Takeaways Google has altered how certain search results function, introducing encoded redirects that obfuscate the true destination URL. This change diminishes the effectiveness of traditional...
Key Takeaways
- Google has altered how certain search results function, introducing encoded redirects that obfuscate the true destination URL.
- This change diminishes the effectiveness of traditional browser link previews as a quick security check, potentially increasing phishing risks for users.
- The new redirects employ a custom Google-specific encoding, making it harder for both users and automated tools to ascertain the final URL without additional steps.
- While Google has not explicitly stated the reason, this modification may aim to hinder large-scale data scraping and combat malicious advertising, but it inadvertently impacts legitimate research and user safety practices.
- There is no immediate fix; users must adopt enhanced verification methods for search results, especially for sensitive queries.
Google has implemented a significant alteration to its search engine’s behavior, modifying how some search results navigate users to external websites. Certain links now route through an encoded Google redirect, rather than directly opening the intended site. This change reduces the utility of a browser’s link preview, a long-standing security measure users employ to quickly verify a link’s destination before clicking.
Table Of Content
This development unfolds amidst a rising tide of cyber threats, including malicious advertising, search-result poisoning, and deceptive download pages, which increasingly leverage ordinary search queries to propagate scams and malware. Users may still observe a familiar site name displayed in the search result, but their ability to cross-reference this label with the actual underlying link has been compromised at the crucial moment of deciding whether to click.
The Mechanics of the New Redirects
Analysts at Malwarebytes reported that Google’s new system utilizes opaque google.com/goto?url= redirects. Crucially, the url parameter within these redirects contains a proprietary Google-specific encoding, rendering the destination unreadable to the average user. This is not indicative of a new malware strain or an active attack campaign; rather, it fundamentally alters a basic browsing habit that users have relied upon to identify suspicious links, as highlighted in a Malwarebytes report. While Google states it employs technical measures against evolving abuse, it has not provided a specific rationale for this particular change. The practical outcome appears to be a heightened difficulty for large-scale extraction of result destinations, as automated tools must now resolve each redirect individually.
Malwarebytes said in a report that the ultimate destination of these links is only visible within the redirect response’s Location header. This additional step impacts not only bulk scrapers but also legitimate tools used for research, archiving, accessibility, rank tracking, and security audits.
Google’s New Search Redirects Make It Harder
For decades, standard cybersecurity advice has included hovering over a search result to inspect the URL displayed in the browser’s status bar before clicking. This quick check can reveal a misspelled domain, an unrelated host, or a suspicious path, all red flags for potential phishing or malware. Under Google’s new system, the link preview may now display an encoded Google address, rather than the actual website a user intends to visit.
Google continues to display the claimed destination above each search result. However, this visible label is no longer independently corroborated by the link preview, removing a crucial layer of verification. This distinction is vital because threat actors frequently manipulate search pages to make malicious destinations appear legitimate. Recent campaigns, for instance, have exploited hijacked Google Ads accounts to direct users to cloned websites and malware downloads via misleading sponsored listings.
It is important to clarify that this change does not inherently mean every goto redirect is malicious, nor does it prove that Google is intentionally directing users to unsafe pages. Instead, it signifies that a common and trusted visual security check now offers diminished assurance. Users should understand that a result title, displayed domain, or even a redirect address should never be considered definitive proof that a download page or sign-in request is legitimate.
The risk associated with this change is particularly acute for searches related to sensitive areas such as software downloads, technical support, banking, or account recovery. Criminals are adept at purchasing or compromising advertising placements and creating highly convincing replicas of trusted brand websites. Reports on poisoned search result campaigns have consistently demonstrated how high-ranking links can lead to fraudulent banking pages designed to steal credentials and active sessions.
Safer Ways to Verify Results
Users are advised to exercise increased caution before clicking on sensitive search results, especially sponsored entries. Rather than relying solely on hover text, users should adopt more robust verification methods. This includes directly typing a known official website address, utilizing a saved bookmark, or navigating from a verified company profile. When seeking software, it is always best to visit the publisher’s official site directly, avoiding advertisements or search results that promise urgent updates.
If a webpage prompts for credentials, payment information, the installation of a browser extension, or a command to paste into a terminal, users should immediately pause and verify the legitimacy of the request through an alternative, trusted channel. This vigilance is particularly critical when a search leads to a support page or an installer. A recent fake Node.js installer campaign, for example, successfully used sponsored search results to lure Windows users into downloading an infostealer.
Organizations that rely on collecting search data should anticipate an increase in requests, potential rate limits, and added costs when attempting to resolve destination URLs. Security teams should update their user awareness guidance to reflect these changes: while hovering over links remains useful in many contexts, it may no longer accurately reveal the final target of these new Google search results. Staff should be trained to validate high-risk links through trusted navigation paths.
The overarching lesson from this update is that search results should not be treated as a security boundary. While these redirects may be intended to mitigate automated abuse, they inadvertently remove a layer of transparency from routine browsing. As evidenced by attacks leveraging trusted Google service routes, familiar infrastructure can become part of a convincing attack chain, making independent verification even more critical before users proceed to click.
What You Should Do
- Exercise Extreme Caution: Do not solely rely on the displayed URL or hover text for sensitive searches (e.g., banking, software, support).
- Direct Navigation: For critical websites, type the known official URL directly into your browser or use verified bookmarks.
- Verify Through Alternative Channels: If a link prompts for credentials or downloads, verify its legitimacy through official company channels (e.g., direct website, official social media, phone support) before proceeding.
- Be Skeptical of Ads: Treat sponsored search results with heightened suspicion, as they are frequently exploited by attackers.
- Educate Users: Organizations should update their security awareness training to inform employees about these changes and emphasize the importance of independent link verification.
- Monitor Network Traffic: Security teams should monitor network traffic for suspicious redirects and unusual outbound connections originating from search clicks.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.