Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Mathspace Data Breach Exposes 1 Million Users’ Personal Info
September 7, 2026
Hackers Hide Credential-Stealing Phishing in Google Services
September 7, 2026
OpenAI Pledges $1 Billion for Critical Infrastructure AI Cybersecurity Tools
September 7, 2026
Home/Threats/Hackers Hide Credential-Stealing Phishing in Google Services
Threats

Hackers Hide Credential-Stealing Phishing in Google Services

Key Takeaways A new, advanced phishing campaign is leveraging legitimate Google services to bypass security filters and steal corporate credentials. The attacks employ sophisticated techniques,...

Sarah simpson
Sarah simpson
September 7, 2026 4 Min Read
2 0

Key Takeaways

  • A new, advanced phishing campaign is leveraging legitimate Google services to bypass security filters and steal corporate credentials.
  • The attacks employ sophisticated techniques, including multi-stage redirects through trusted Google domains and personalized phishing pages.
  • Beyond credential theft, some variants of the campaign install ScreenConnect for remote access, posing a significant threat of persistent control.
  • Organizations in manufacturing, government, finance, and non-profit sectors are being targeted.
  • Detection is challenging due to the use of trusted infrastructure and dynamic page generation.

Cybercriminals are orchestrating a sophisticated phishing campaign that exploits the inherent trust in Google’s services to compromise corporate credentials and, in some instances, deploy remote access tools. This malicious operation routes victims through multiple legitimate Google-owned domains, effectively evading traditional security measures before ultimately directing them to attacker-controlled pages designed for credential harvesting or malware delivery.

Table Of Content

  • Key Takeaways
  • Hackers Abuse Trusted Google Services
  • Personalized Pages and Remote Access

The phishing emails are crafted to mimic common workplace communications, including notifications for document reviews, expiring mailboxes, package deliveries, payment alerts, voicemail messages, and government benefits. These lures are specifically targeting employees across a diverse range of sectors, including manufacturing, government, finance, and non-profit organizations.

Analysts at KnowBe4 Threat Lab have identified this activity as a deliberate strategy to transform trusted web infrastructure into a “trust proxy.” According to a KnowBe4 report, victims are either led to convincing credential-harvesting pages or, in more insidious cases, a deceptive verification process that covertly installs ScreenConnect, a legitimate remote management software often abused by threat actors.

The ramifications of a successful attack extend beyond mere password compromise. Stolen credentials can grant attackers unauthorized access to email accounts, cloud storage, and internal corporate services. Furthermore, an illicit remote-access session can provide persistent control over an employee’s workstation, enabling further reconnaissance, data exfiltration, or the deployment of additional malware. The combination of trusted links, highly personalized phishing pages, and evasion techniques makes this campaign particularly difficult for both human users and automated security systems to detect.

Hackers Abuse Trusted Google Services

Instead of embedding easily identifiable malicious links in their phishing emails, the attackers guide recipients through a sequence of authentic Google endpoints. This multi-stage redirection significantly enhances the campaign’s stealth and legitimacy.

Observed attack paths involve various Google services such as Google Meet, Google Search, DoubleClick, Custom Search, Image Search, Tag Manager, and Analytics. Some chains utilize several of these services before the user’s browser ever leaves Google’s infrastructure. This tactic echoes previous Google OAuth phishing flaws, where the legitimacy of Google’s infrastructure can inadvertently lend credibility to malicious messages. The presence of a trusted intermediate domain does not guarantee the trustworthiness of the ultimate destination or any subsequent requests or downloads.

The campaign further enhances its evasiveness by appending the target’s email address after the hash symbol (#) in the URL, sometimes in a base64 encoded format. Web browsers are designed not to transmit this URL fragment to web servers, effectively hiding this personalized targeting data from server logs and many URL-scanning systems. This technique allows the final phishing page to identify the arriving user without exposing the targeting information throughout the redirect chain.

Personalized Pages and Remote Access

Upon reaching the final stage of redirection, the phishing kit performs several checks before displaying a login form. These checks can include gathering location and browser details, verifying the target email domain’s mail records, and presenting fake human-verification screens. These measures are designed to filter out automated analysis tools and ensure that only legitimate targets are presented with the credential-stealing page, making the operation more selective and harder to disrupt.

The final phishing page is meticulously tailored using the victim’s email address. It can dynamically retrieve and display the target organization’s logo, embed a live screenshot of their actual website as a background, pre-fill the recipient’s email address, and render text in the browser’s native language. This high degree of personalization significantly increases the perceived authenticity of the fake sign-in request, making it more convincing to unsuspecting users.

Once a victim submits their password, the phishing kit immediately transmits the credentials, along with technical details, to a Telegram bot. A deceptive tactic then comes into play: the page intentionally reports an “invalid password” error and prompts for a second entry. This strategy is designed to capture a second credential pair, increasing the chances of success, before finally redirecting the victim to their legitimate company website. This pattern has been observed in other campaigns, such as the fake invitation phishing campaigns.

In a distinct but related attack vector, the campaign masquerades as an identity verification process, which covertly installs ScreenConnect. This legitimate remote-management tool can then be leveraged by attackers to establish persistent access to compromised systems, highlighting how trusted software can be weaponized. Recent <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/a9900f83-d7d0-4023-a50c-55281065924b/Hackers-Abuse-Trusted-Google-Services-to-Hide-Credential-Stealing-Phishing-Attacks.pdf?AWSAccessKeyId=ASIA2F3EMEYER2YRUXYZ&Signature=WHF2x8aL%2FfmUzl17isBL%2BZU30sc%3D&x-amz-security-

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerMalwarephishingSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

OpenAI Pledges $1 Billion for Critical Infrastructure AI Cybersecurity Tools

Next Post

Mathspace Data Breach Exposes 1 Million Users’ Personal Info

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
ConnectWise Patches Critical ScreenConnect Vulnerability CVE-2024-46805
September 7, 2026
New Linux Botnet Masquerades as Kernel Process to Launch DDoS Attacks
September 7, 2026
LG Smart TVs Vulnerable to Network Scanning and Audio Logging in Standby
September 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us