Attackers Use Multi-Hop Google Redirects for Phishing Campaign
Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access.
Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access. Attackers are chaining together multiple Google services in order to get phishing links past security gateways. 4 concerning an ongoing phishing campaign observed in the wild. To some extent, the mechanics of the campaign are typical: The threat actor sends a malicious email under false pretenses, the victim clicks the link, and the link leads to a malicious landing page where the victim is compromised.
In others, a script installs ScreenConnect as a remote access tool via a fake identity verification prompt. He has received numerous awards, including TechTarget's Writer of the Year in 2022 as well as more than 10 Azbee awards for his reporting between 2022 and today. Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy How to Leverage Threat Intelligence Without Drowning: The Zero Noise Approach Check out the Black Hat USA 2026 Conference Guide for coverage and intel from — and about — the show! This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers.
Related: 'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink "By the time a defender inspects the sending domain, the embedded link, or the intermediate hops, everything still looks clean.
What changed
Attackers regularly lean on redirects through legitimate infrastructure and have for years , but this method stands out because the threat campaign deliberately uses multiple Google services within the redirection chain.
KnowBe4 threat analysts Prabhakaran Ravichandhiran and Jeewan Singh Jalal described a three-hop redirect chain that uses services including Google Meet, DoubleClick ad infrastructure, Google Custom Search, Google Image Search, Google Tag Manager, and Google Analytics.
"Most phishing campaigns embed a malicious link and bet on the gateway missing it.
As far as lures go, KnowBe4 says the campaign does not adhere to one single type but rather a range of business contexts.
Once the victim's credentials are entered, they're delivered to the operator's Telegram channel within seconds, along with other information including "the victim's IP address, geolocation, browser string and verified MX records for their organization." The campaign appears to be targeted rather than indiscriminate, based on how the phishing URLs are constructed.
"Victim email addresses are encoded in base64 and hidden in the URL hash fragment, which browsers strip before sending any request, making it invisible to server-side logs and most URL scanners, effectively masking the pre-targeted nature of the campaign," the blog post read.
Who is affected
Notably, once the victim clicks a phishing link, the landing page's JavaScript dynamically constructs a credential harvesting landing page from the victim's email address alone, displaying a live screenshot of the victim's corporate website behind the login page.
James Dyer, head of threat intelligence at KnowBe4, tells Dark Reading that even organizations with basic protections against phishing may not be safe.
Additionally, while phishing-resistant MFA is important, "It fails against this campaign's two other paths, device-code interception and RMM delivery." "Neither path touches a login form, so there's no MFA challenge to protect," he says.
Related: Threat Actor Generates 1M Personalized Fraud Emails in 3 Days KnowBe4's research includes indicators of compromise (IoCs) as well as recommendations to block the IoCs at the DNS filter, proxy, and SIEM level now; hunt for Telegram bot API traffic; force credential resets for users that may have received lures associated with this campaign; hunt for unauthorized ScreenConnect installations or activity; and alert users to the URL fragment technique.
Why this matters
In others, a script installs ScreenConnect as a remote access tool via a fake identity verification prompt.
He has received numerous awards, including TechTarget's Writer of the Year in 2022 as well as more than 10 Azbee awards for his reporting between 2022 and today.
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy How to Leverage Threat Intelligence Without Drowning: The Zero Noise Approach Check out the Black Hat USA 2026 Conference Guide for coverage and intel from — and about — the show!
This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers.
The technical picture
Related: 'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink "By the time a defender inspects the sending domain, the embedded link, or the intermediate hops, everything still looks clean.
What to watch next
Watch for additional exploitation reporting, newly published indicators, and changes to vendor guidance.