A flow diagram representing the abuse of Google services | Image: KnowBe4 Threat Lab
At a glance
Threat researchers from the KnowBe4 Threat Lab uncovered a highly sophisticated phishing campaign recently. The attackers systematically abuse Google infrastructure to bypass corporate email security gateways and harvest credentials.
| Category | Details |
|---|---|
| Actor or Group | Unattributed threat actor |
| Activity Type | Credential harvesting and remote access tool (RAT) deployment |
| Targets or Victims | Corporate employees across manufacturing, finance, government, and NGOs |
| Scale | Global operation targeting 16 language locales |
| Jurisdiction Status | Tracked by private security researchers |
| Source | KnowBe4 Threat Lab Analysis |
Executive Summary
The attackers designed a multi-hop phishing chain that exclusively uses legitimate Google domains to bypass security filters. By the time a target reaches the malicious landing page, the attackers deploy ScreenConnect or steal credentials. Security teams must monitor URL fragments and analyze the complete redirect chain to block this threat.
How the Phishing Chain Works
Most phishing operations rely on security gateways missing a malicious link. However, this campaign operates differently. According to the report, “This one does not need the gateway to miss anything. It feeds the gateway exactly what it expects: trusted Google domains at every hop.”
The attackers use lures ranging from expired Microsoft 365 passwords to fake FedEx package deliveries. When a victim clicks the link, they initiate a complex redirect sequence. The chain routes the victim through Google Meet, Google Custom Search, DoubleClick, and Google Tag Manager.
Because these domains enjoy high trust ratings, security scanners rarely block them. Furthermore, the attackers hide the victim’s email address inside the URL hash fragment. As the report explains, “Victim email addresses are encoded in base64 and hidden in the URL hash fragment, which browsers strip before sending any request, making it invisible to server-side logs and most URL scanners.”
Once the redirects complete, the victim lands on a dynamically generated phishing page. The attackers use the Clearbit API to pull the victim’s real corporate logo and take a live screenshot of their company website. Consequently, the user sees a familiar, highly customized login prompt.
Who Is Behind the Attack
Researchers have not yet attributed this campaign to a specific advanced persistent threat (APT) group. However, the sophisticated engineering suggests a highly organized cybercrime syndicate. The attackers built the harvester UI to localize itself into 16 different languages, indicating a global targeting scope.
Impact and Scale of the Operation
The campaign features a dual-track execution model. The first track steals credentials. When a user submits their password, the system intentionally rejects it. As the researchers noted, “The first submission always returns an ‘Invalid password’ error and clears the field, regardless of what was entered.” The victim re-enters their password, giving the attackers a high-confidence credential pair. The system then exfiltrates this data immediately to a Telegram bot.
Alternatively, the second track deploys a persistent remote access tool. Victims encounter a fake identity verification screen that silently installs ConnectWise ScreenConnect in the background. This grants the attackers persistent remote access to the corporate endpoint, bypassing multi-factor authentication.
Defending Against Google Infrastructure Abuse
Security teams must adapt their defenses immediately. Because attackers abuse Google infrastructure to bypass standard filters, traditional domain blocking is ineffective. Organizations must train employees to scrutinize the final URL landing page, not just the initial link. Additionally, endpoint detection systems must monitor for unauthorized silent installations of remote management tools like ScreenConnect.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!