Cyber attackers are cleverly manipulating Google services to execute extensive phishing operations, targeting corporate credentials and occasionally installing remote-access tools. This deceptive strategy utilizes Google-owned domains before redirecting users to malicious pages controlled by the attackers.
Phishing Techniques Targeting Various Sectors
The phishing emails often mimic typical workplace communications, such as document reviews, mailbox expiration alerts, package delivery notifications, payment reminders, voicemail alerts, and government benefits notices. These emails are directed at employees in sectors like manufacturing, government, finance, and non-profit organizations.
According to analysts at KnowBe4 Threat Lab, the campaign is designed to leverage trusted web infrastructure as a ‘trust proxy.’ Their report, shared with Cyber Security News (CSN), indicates that victims might be led to pages that either harvest credentials or initiate a fake verification process that installs ScreenConnect.
Implications of Credential Theft and Unauthorized Access
The consequences of these phishing attacks extend beyond merely obtaining passwords. A successful credential theft can grant access to emails, cloud files, and internal services, while unauthorized remote access sessions enable intruders to maintain control over the victim’s workstation.
The use of trusted Google services, along with personalized pages and scanner checks, complicates detection for average users and automated defense systems. Rather than using obvious phishing addresses, attackers guide recipients through legitimate Google endpoints.
Complex Phishing Routes and Their Execution
Observed routes include services like Google Meet, Google Search, DoubleClick, Custom Search, Image Search, Tag Manager, and Analytics. These routes often employ several services before leaving Google’s infrastructure. Such tactics enhance the credibility of fraudulent messages.
One example involves a sequence starting with Google Meet, continuing through Google Search, and utilizing DoubleClick for click tracking. Other variants may use Google Custom Search redirects or involve regional Image Search domains and Analytics parameters, all appearing normal to domain reputation-based tools.
Protective Measures Against Phishing Scams
Organizations are advised to reset credentials for exposed users, check for unauthorized installations of tools like ScreenConnect, block known threat indicators at DNS and proxy levels, monitor traffic to Telegram Bot APIs, and report abusive redirect URLs to Google Safe Browsing.
Recent attacks involving ScreenConnect highlight the potential for trusted remote-support tools to escalate incidents from a single click. Staying informed about active malware and phishing threats is critical for maintaining cybersecurity defenses.
