ZeroHour
Dark Readingpublished ()ingested Alexander Culafi

Attackers Use Multi-Hop Google Redirects for Phishing Campaign

mediumPhishing & fraud exploited in the wildimportance 48
AI summary · glm-5.3-flash

Threat actors chain multiple legitimate Google service redirects to evade detection and deliver credential harvesting or ScreenConnect remote access tooling.

Threat actors are abusing multiple legitimate Google services to build multi-hop redirect chains that obscure the final destination and bypass reputation-based filtering. The campaign culminates in credential harvesting pages or silent installation of the ScreenConnect remote access tool. Defenders should watch for links that traverse trusted Google domains before landing on malicious endpoints.

  • Multi-hop redirects through legitimate Google services hide the final phishing destination.
  • Payloads include credential harvesting or ScreenConnect remote access installation.
  • Trusted Google domains help malicious links evade reputation-based email and web filtering.
OrganizationsGoogle
Full article

Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access.

The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at darkreading.com.