Phishing Campaign Abuses Google Services to Create Multi-Hop Redirect Links for Data Theft and Device Control

Views: 38 views

496/69 Thursday, September 10, 2026

In early September, cybersecurity researchers from KnowBe4 reported the discovery of a new phishing campaign in which threat actors abused features across multiple Google services to evade detection by security systems. The attackers created a redirection chain using trusted Google domains to deceive email filtering systems and other security tools, allowing phishing emails to reach target users’ inboxes. This puts organizations at risk of sensitive data theft or unauthorized control of users’ computers.

In this attack, the threat actors built a three-stage link redirection chain through legitimate Google infrastructure, including Google Meet, DoubleClick, Google Custom Search, and Google Analytics. As a result, front-line security systems initially see only trusted domains. When users click links in phishing emails, which are often disguised as parcel notifications, document verification requests, or payment notices, they are redirected to fake websites carefully designed to mimic the login pages of their organizations in order to steal passwords. In some cases, the attack may display a fake verification page to covertly install remote control software such as ScreenConnect. Stolen information is immediately sent to the attackers’ Telegram channel, along with the victim’s location and browser details. The attackers also encode and hide the target email address at the end of the URL after the hash symbol (#), helping the link bypass server-side scanning and indicating that the attack is targeted.

To reduce risk and mitigate potential impact from this campaign, administrators should block related domains and indicators of compromise (IOCs) at the DNS, proxy, and SIEM levels. They should also monitor traffic connected to Telegram infrastructure and closely inspect any unauthorized ScreenConnect installations within the organization. For users who may have been targeted or may have received phishing emails of this type, administrators should require an immediate password reset. Organizations should also inform users to be cautious and carefully inspect links attached to emails, especially if a URL contains a hash symbol (#) followed by unusual text, as this may indicate a malicious link crafted for targeted attacks.

Source: https://www.darkreading.com/cyberattacks-data-breaches/attackers-multi-hop-google-redirects-phishing-campaign