Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Linux Kernel SCTP Vulnerability Lets Attackers Gain Root
August 7, 2026
Critical WordPress XSS2Shell Flaw Allows Remote Code Execution
August 7, 2026
Critical Windows Hello for Business Bug Lets Attackers Impersonate Users in Entra ID
August 7, 2026
Home/Threats/Attackers Exploit Google Cloud for Stealthy Phishing Campaigns
Threats

Attackers Exploit Google Cloud for Stealthy Phishing Campaigns

Key Takeaways Phishing campaigns are leveraging legitimate Google Cloud services to bypass email security defenses. Attackers use a “nested, triple-chain” of Google domains (Meet, Search...

Jennifer sherman
Jennifer sherman
May 27, 2026 4 Min Read
62 0

Key Takeaways

  • Phishing campaigns are leveraging legitimate Google Cloud services to bypass email security defenses.
  • Attackers use a “nested, triple-chain” of Google domains (Meet, Search Redirect, Ad Service) to hide malicious links.
  • The attacks lead to credential theft via fake Microsoft 365 login pages or session hijacking through device code phishing.
  • The technique exploits the trust placed in major tech platforms, making detection difficult for automated systems.

Attackers Exploit Google Cloud for Stealthy Phishing Campaigns

Cybercriminals are increasingly sophisticated in their phishing tactics, finding new ways to circumvent traditional security measures. A recent campaign highlights a particularly insidious method: weaponizing the inherent trust in major technology platforms like Google Cloud to deliver highly deceptive phishing lures.

Table Of Content

  • Key Takeaways
  • Attackers Exploit Google Cloud for Stealthy Phishing Campaigns
  • Triple-Chain Delivery Evades Detection
  • Hackers Abuse Trusted Google Domains
  • Credential Theft and Session Hijacking: The Two-Pronged Payload
  • What You Should Do

This novel approach involves embedding malicious links within a sequence of legitimate Google services, effectively rendering many automated email security systems blind. By presenting a chain of trusted Google domains, the true, nefarious destination of the link remains concealed until a human user interacts with it. This critical gap between machine analysis and human interaction is precisely what attackers are exploiting.

Triple-Chain Delivery Evades Detection

Researchers at KnowBe4 ThreatLabs have been actively tracking this campaign. They identified a “triple-chain” delivery method that significantly enhances its ability to evade detection. This technique sequentially utilizes three distinct Google services—Google Meet, Google Search Redirect, and Google Ad Service—to reroute victims to phishing sites without triggering security alarms.

The lures employed are crafted to induce a sense of urgency, compelling recipients to click. Common themes include fake FedEx delivery updates, fraudulent DocuSign and AutoSign requests, fabricated Microsoft 365 password expiry notifications, bogus payment remittances, and emails containing malicious QR codes.

Upon clicking, victims are led down one of two paths. Some are directed to meticulously crafted Microsoft 365 sign-in pages, often with their email address pre-filled, designed to steal credentials. Others encounter a deceptive OneDrive shared document preview featuring a pre-generated Microsoft device code. If entered, this code grants attackers full access to the victim’s corporate account, bypassing the need for a password and potentially multi-factor authentication.

Hackers Abuse Trusted Google Domains

The core innovation of this attack, dubbed the “Nested Delivery Matrix” by researchers, lies in its URL construction. Attackers engineer a URL that traverses three legitimate Google-owned domains before finally redirecting to the attacker-controlled phishing site. The typical redirection chain observed is: SafeLinks > meet.google.com/linkredirect > google.com/url > adservice.google.com.ph > malicious page.

Email security gateways, when inspecting this chain, find no suspicious indicators because every domain in the redirect path is a legitimate Google property. With clean reputation scores, the email is then deemed safe and delivered to the recipient’s inbox, unaware of the malicious final destination awaiting an unsuspecting click.

Credential Theft and Session Hijacking: The Two-Pronged Payload

Once a victim lands on the phishing page, the attack unfolds in one of two primary ways. The first is a classic credential harvesting operation, where a convincing, fake Microsoft 365 login page captures usernames and passwords. The danger is amplified by the pre-population of the victim’s email address on the page, lending an air of authenticity that lowers suspicion.

The second outcome is more advanced: session hijacking. Victims are presented with a simulated OneDrive document preview, which includes a Microsoft device authentication code. Should the victim input this code into a genuine Microsoft login page, the attacker can silently gain access to their corporate session. This technique, known as device code phishing, is particularly potent as it circumvents password requirements and can bypass multi-factor authentication entirely.

What You Should Do

  • Educate employees to scrutinize all links, even those appearing to originate from trusted domains, and to hover over URLs to reveal their true destination before clicking.
  • Advise users to be wary of pre-populated login forms on unexpected sign-in pages and to report any unusual device code prompts immediately.
  • Implement and enforce robust email security gateway policies that can block unknown or suspicious redirect patterns, even if they pass through trusted domains initially.
  • Enable and configure conditional access policies within Microsoft environments to restrict access based on device, location, and other contextual factors.
  • Regularly review and update security awareness training to include the latest phishing tactics, such as nested redirect chains and device code phishing.

Indicators of Compromise (IoCs):-

Type Indicator Description
Domain vazquezfleytas[.]com Attacker-controlled phishing domain
Domain edificiocristal[.]pt Attacker-controlled phishing domain
Domain velvorra[.]com Attacker-controlled phishing domain
Domain furqanmustafa[.]com Attacker-controlled phishing domain
Domain unitedtechnofzmlogies[.]vu Attacker-controlled phishing domain
Domain cloudbemismanufacturingcompanygroup[.]rydezyhrsysteminc[.]vu Attacker-controlled phishing domain
Domain servicetriumphgroupsimplyappraisals[.]spectrhwqumbrands[.]vu Attacker-controlled phishing domain
Domain cloudgillettebrandberkshirehathaway[.]rtzcoekdrporation[.]vu Attacker-controlled phishing domain
Domain odahlzr5lm[.]reliabilityinoperations[.]de Attacker-controlled phishing domain
App/Domain staiwooje[.]app Attacker-controlled phishing endpoint
Cloudflare Worker URL Link-form-unj9[.]p-sm7rw6ru[.]workers[.]dev Malicious Cloudflare Workers delivery URL
Cloudflare Worker URL data-cloud-ofe8[.]p-8yejy42o[.]workers[.]dev Malicious Cloudflare Workers delivery URL

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerphishingSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Apple iOS 17.3 New Stolen Device Protection Feature Auto-Locks iPhones

Next Post

Seedworm APT uses DLL sideloading with signed Fortemedia, SentinelOne binaries

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Patchwork APT Uses Fake PDFs, Chat Apps to Spy on PCs, Android
August 7, 2026
Claude in Chrome Prompt Injection Steals Gmail Codes to Hijack Slack, X, and Claude.ai Accounts
August 7, 2026
Critical SharePoint Vulnerability Let Hackers Breach Swiss Government
August 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us