Hackers Hide Credential-Stealing Phishing in Google Services
Key Takeaways A new, advanced phishing campaign is leveraging legitimate Google services to bypass security filters and steal corporate credentials. The attacks employ sophisticated techniques,...
Key Takeaways
- A new, advanced phishing campaign is leveraging legitimate Google services to bypass security filters and steal corporate credentials.
- The attacks employ sophisticated techniques, including multi-stage redirects through trusted Google domains and personalized phishing pages.
- Beyond credential theft, some variants of the campaign install ScreenConnect for remote access, posing a significant threat of persistent control.
- Organizations in manufacturing, government, finance, and non-profit sectors are being targeted.
- Detection is challenging due to the use of trusted infrastructure and dynamic page generation.
Cybercriminals are orchestrating a sophisticated phishing campaign that exploits the inherent trust in Google’s services to compromise corporate credentials and, in some instances, deploy remote access tools. This malicious operation routes victims through multiple legitimate Google-owned domains, effectively evading traditional security measures before ultimately directing them to attacker-controlled pages designed for credential harvesting or malware delivery.
Table Of Content
The phishing emails are crafted to mimic common workplace communications, including notifications for document reviews, expiring mailboxes, package deliveries, payment alerts, voicemail messages, and government benefits. These lures are specifically targeting employees across a diverse range of sectors, including manufacturing, government, finance, and non-profit organizations.
Analysts at KnowBe4 Threat Lab have identified this activity as a deliberate strategy to transform trusted web infrastructure into a “trust proxy.” According to a KnowBe4 report, victims are either led to convincing credential-harvesting pages or, in more insidious cases, a deceptive verification process that covertly installs ScreenConnect, a legitimate remote management software often abused by threat actors.
The ramifications of a successful attack extend beyond mere password compromise. Stolen credentials can grant attackers unauthorized access to email accounts, cloud storage, and internal corporate services. Furthermore, an illicit remote-access session can provide persistent control over an employee’s workstation, enabling further reconnaissance, data exfiltration, or the deployment of additional malware. The combination of trusted links, highly personalized phishing pages, and evasion techniques makes this campaign particularly difficult for both human users and automated security systems to detect.
Hackers Abuse Trusted Google Services
Instead of embedding easily identifiable malicious links in their phishing emails, the attackers guide recipients through a sequence of authentic Google endpoints. This multi-stage redirection significantly enhances the campaign’s stealth and legitimacy.
Observed attack paths involve various Google services such as Google Meet, Google Search, DoubleClick, Custom Search, Image Search, Tag Manager, and Analytics. Some chains utilize several of these services before the user’s browser ever leaves Google’s infrastructure. This tactic echoes previous Google OAuth phishing flaws, where the legitimacy of Google’s infrastructure can inadvertently lend credibility to malicious messages. The presence of a trusted intermediate domain does not guarantee the trustworthiness of the ultimate destination or any subsequent requests or downloads.
The campaign further enhances its evasiveness by appending the target’s email address after the hash symbol (#) in the URL, sometimes in a base64 encoded format. Web browsers are designed not to transmit this URL fragment to web servers, effectively hiding this personalized targeting data from server logs and many URL-scanning systems. This technique allows the final phishing page to identify the arriving user without exposing the targeting information throughout the redirect chain.
Personalized Pages and Remote Access
Upon reaching the final stage of redirection, the phishing kit performs several checks before displaying a login form. These checks can include gathering location and browser details, verifying the target email domain’s mail records, and presenting fake human-verification screens. These measures are designed to filter out automated analysis tools and ensure that only legitimate targets are presented with the credential-stealing page, making the operation more selective and harder to disrupt.
The final phishing page is meticulously tailored using the victim’s email address. It can dynamically retrieve and display the target organization’s logo, embed a live screenshot of their actual website as a background, pre-fill the recipient’s email address, and render text in the browser’s native language. This high degree of personalization significantly increases the perceived authenticity of the fake sign-in request, making it more convincing to unsuspecting users.
Once a victim submits their password, the phishing kit immediately transmits the credentials, along with technical details, to a Telegram bot. A deceptive tactic then comes into play: the page intentionally reports an “invalid password” error and prompts for a second entry. This strategy is designed to capture a second credential pair, increasing the chances of success, before finally redirecting the victim to their legitimate company website. This pattern has been observed in other campaigns, such as the fake invitation phishing campaigns.
In a distinct but related attack vector, the campaign masquerades as an identity verification process, which covertly installs ScreenConnect. This legitimate remote-management tool can then be leveraged by attackers to establish persistent access to compromised systems, highlighting how trusted software can be weaponized. Recent <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/a9900f83-d7d0-4023-a50c-55281065924b/Hackers-Abuse-Trusted-Google-Services-to-Hide-Credential-Stealing-Phishing-Attacks.pdf?AWSAccessKeyId=ASIA2F3EMEYER2YRUXYZ&Signature=WHF2x8aL%2FfmUzl17isBL%2BZU30sc%3D&x-amz-security-
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.