Attackers Exploit Google Cloud for Stealthy Phishing Campaigns
Key Takeaways Phishing campaigns are leveraging legitimate Google Cloud services to bypass email security defenses. Attackers use a “nested, triple-chain” of Google domains (Meet, Search...
Key Takeaways
- Phishing campaigns are leveraging legitimate Google Cloud services to bypass email security defenses.
- Attackers use a “nested, triple-chain” of Google domains (Meet, Search Redirect, Ad Service) to hide malicious links.
- The attacks lead to credential theft via fake Microsoft 365 login pages or session hijacking through device code phishing.
- The technique exploits the trust placed in major tech platforms, making detection difficult for automated systems.
Attackers Exploit Google Cloud for Stealthy Phishing Campaigns
Cybercriminals are increasingly sophisticated in their phishing tactics, finding new ways to circumvent traditional security measures. A recent campaign highlights a particularly insidious method: weaponizing the inherent trust in major technology platforms like Google Cloud to deliver highly deceptive phishing lures.
Table Of Content
This novel approach involves embedding malicious links within a sequence of legitimate Google services, effectively rendering many automated email security systems blind. By presenting a chain of trusted Google domains, the true, nefarious destination of the link remains concealed until a human user interacts with it. This critical gap between machine analysis and human interaction is precisely what attackers are exploiting.
Triple-Chain Delivery Evades Detection
Researchers at KnowBe4 ThreatLabs have been actively tracking this campaign. They identified a “triple-chain” delivery method that significantly enhances its ability to evade detection. This technique sequentially utilizes three distinct Google services—Google Meet, Google Search Redirect, and Google Ad Service—to reroute victims to phishing sites without triggering security alarms.
The lures employed are crafted to induce a sense of urgency, compelling recipients to click. Common themes include fake FedEx delivery updates, fraudulent DocuSign and AutoSign requests, fabricated Microsoft 365 password expiry notifications, bogus payment remittances, and emails containing malicious QR codes.
Upon clicking, victims are led down one of two paths. Some are directed to meticulously crafted Microsoft 365 sign-in pages, often with their email address pre-filled, designed to steal credentials. Others encounter a deceptive OneDrive shared document preview featuring a pre-generated Microsoft device code. If entered, this code grants attackers full access to the victim’s corporate account, bypassing the need for a password and potentially multi-factor authentication.
Hackers Abuse Trusted Google Domains
The core innovation of this attack, dubbed the “Nested Delivery Matrix” by researchers, lies in its URL construction. Attackers engineer a URL that traverses three legitimate Google-owned domains before finally redirecting to the attacker-controlled phishing site. The typical redirection chain observed is: SafeLinks > meet.google.com/linkredirect > google.com/url > adservice.google.com.ph > malicious page.
Email security gateways, when inspecting this chain, find no suspicious indicators because every domain in the redirect path is a legitimate Google property. With clean reputation scores, the email is then deemed safe and delivered to the recipient’s inbox, unaware of the malicious final destination awaiting an unsuspecting click.
Credential Theft and Session Hijacking: The Two-Pronged Payload
Once a victim lands on the phishing page, the attack unfolds in one of two primary ways. The first is a classic credential harvesting operation, where a convincing, fake Microsoft 365 login page captures usernames and passwords. The danger is amplified by the pre-population of the victim’s email address on the page, lending an air of authenticity that lowers suspicion.
The second outcome is more advanced: session hijacking. Victims are presented with a simulated OneDrive document preview, which includes a Microsoft device authentication code. Should the victim input this code into a genuine Microsoft login page, the attacker can silently gain access to their corporate session. This technique, known as device code phishing, is particularly potent as it circumvents password requirements and can bypass multi-factor authentication entirely.
What You Should Do
- Educate employees to scrutinize all links, even those appearing to originate from trusted domains, and to hover over URLs to reveal their true destination before clicking.
- Advise users to be wary of pre-populated login forms on unexpected sign-in pages and to report any unusual device code prompts immediately.
- Implement and enforce robust email security gateway policies that can block unknown or suspicious redirect patterns, even if they pass through trusted domains initially.
- Enable and configure conditional access policies within Microsoft environments to restrict access based on device, location, and other contextual factors.
- Regularly review and update security awareness training to include the latest phishing tactics, such as nested redirect chains and device code phishing.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Domain | vazquezfleytas[.]com | Attacker-controlled phishing domain |
| Domain | edificiocristal[.]pt | Attacker-controlled phishing domain |
| Domain | velvorra[.]com | Attacker-controlled phishing domain |
| Domain | furqanmustafa[.]com | Attacker-controlled phishing domain |
| Domain | unitedtechnofzmlogies[.]vu | Attacker-controlled phishing domain |
| Domain | cloudbemismanufacturingcompanygroup[.]rydezyhrsysteminc[.]vu | Attacker-controlled phishing domain |
| Domain | servicetriumphgroupsimplyappraisals[.]spectrhwqumbrands[.]vu | Attacker-controlled phishing domain |
| Domain | cloudgillettebrandberkshirehathaway[.]rtzcoekdrporation[.]vu | Attacker-controlled phishing domain |
| Domain | odahlzr5lm[.]reliabilityinoperations[.]de | Attacker-controlled phishing domain |
| App/Domain | staiwooje[.]app | Attacker-controlled phishing endpoint |
| Cloudflare Worker URL | Link-form-unj9[.]p-sm7rw6ru[.]workers[.]dev | Malicious Cloudflare Workers delivery URL |
| Cloudflare Worker URL | data-cloud-ofe8[.]p-8yejy42o[.]workers[.]dev | Malicious Cloudflare Workers delivery URL |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.