Google’s New Search Redirects Make It Harder to Check Where Links Lead Before Clicking
Malwarebytes reports Google's new encoded google.com/goto?url= redirects break hover-preview link checking, weakening a common phishing defense.
Google now routes some search results through opaque google.com/goto?url= redirects using custom encoding, so browser link previews no longer reveal the true destination, only the claimed label above the result. Malwarebytes found the final destination is visible only in the redirect response's Location header, complicating hover-based safety checks as well as scraping, archiving, and audit tools. The change arrives amid malvertising, search-result poisoning, and fake installer campaigns like the recent Node.js infostealer lure. Google says it deploys measures against evolving abuse but did not explain the change.
- Encoded google.com/goto?url= redirects hide final destinations from hover previews
- Destination only visible via redirect response Location header
- Weakens standard advice for spotting phishing and fake download pages
- Also impacts scrapers, archiving, accessibility, and rank-tracking tools
Full article787 words · extracted from cybersecuritynews.com · click to collapse
Google is changing how some search-result links behave. Certain results now pass through an encoded Google redirect rather than opening the listed site, making a browser’s link preview less useful as a quick safety check.
The change comes as malicious advertising, search-result poisoning, and lookalike download pages keep turning ordinary searches into routes for scams and malware.
Users may still see a familiar site name in the result, but their ability to compare that label with the actual link has weakened at the moment they decide whether to click.
Analysts at Malwarebytes noted that the rollout uses opaque google.com/goto?url= redirects whose url parameter contains a custom Google-specific encoding instead of a readable destination.
This is not a newly discovered malware family or a confirmed attack campaign, but it changes a basic browsing habit used to spot suspicious links.
Google says it deploys technical measures against evolving abuse, but has not specified the reason for this change. The apparent effect is to make large-scale extraction of result destinations harder because automated tools must resolve each redirect separately.
Malwarebytes said in a report shared with Cyber Security News (CSN) that the final destination is viewable only through the redirect response’s Location header. The extra request affects bulk scrapers and legitimate research, archiving, accessibility, rank tracking, and audit tools.
Google’s New Search Redirects Make It Harder
For years, standard safety advice has been to hover over a search result and inspect the address displayed by the browser before clicking.
That check can expose a misspelled domain, unrelated host, or suspicious path. Under the new system, the preview may show an encoded Google address rather than the website a user expects to visit.
Google still displays the claimed destination above the result, but that label is no longer independently confirmed by the link preview.
The distinction matters because attackers use search pages to make harmful destinations look ordinary. Recent campaigns abusing hijacked Google Ads accounts have sent users to clone sites and malware downloads after misleading sponsored listings.
This does not mean every goto redirect is malicious, or prove that Google is directing users to unsafe pages. It does mean a familiar visual check offers less assurance.
.webp)
A result title, displayed domain, or redirect address should not be treated as proof that a download page or sign-in request is legitimate.
The risk is sharper for searches involving software, technical support, banking, or account recovery. Criminals can buy or compromise advertising placements and create pages that closely copy trusted brands.
Reporting on poisoned search result campaigns shows how high-ranking links can lead to fraudulent banking pages that capture passwords and active sessions.
Safer Ways to Verify Results
Users should take an extra moment before opening sensitive results, especially sponsored entries. Rather than relying on hover text alone, type a known official address, use a saved bookmark, or navigate from a verified company profile.
For software, reach the publisher’s site directly instead of following an ad or a result promising an urgent update. If a page asks for credentials, payment data, a browser extension, or a command to paste into a terminal, stop and verify through another route.
This matters when a search leads to a support page or installer. A recent fake Node.js installer campaign used sponsored results to lure Windows users toward an infostealer.
Organizations that collect search data should expect more requests, possible rate limits, and added cost when resolving destinations.
Security teams can update awareness guidance: hovering remains useful in many contexts, but it may not disclose the final target of these results. Staff should validate high-risk links through trusted navigation paths.
The broader lesson is that search results are not a security boundary. Redirects may be intended to curb automated abuse, but they remove a layer of transparency from everyday browsing.
As attacks using trusted Google service routes show, familiar infrastructure can be part of a convincing chain, making independent verification more important before users click.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| URL pattern | google.com/goto?url=... | Encoded Google Search redirect URL pattern described in the source material. |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/googles-new-search/