Large-Scale Phishing Operation Exploiting Google Services
A sophisticated phishing campaign has emerged, leveraging trusted Google services as a multifaceted redirect network designed to bypass standard email security measures. This operation not only aims to capture user credentials through highly personalized phishing pages but also, in some instances, to install remote-access software such as ScreenConnect on victims’ devices.
The Mechanics of the Campaign
The primary strength of this phishing campaign lies in its ability to present highly trusted Google-owned domains at almost every juncture that security analysts or automated systems might scrutinize. Unlike traditional phishing tactics that usually rely on malicious URLs, this operation employs legitimate redirect and tracking functionalities as a form of trust proxy. This method skillfully delays detection of the final phishing destination until after the initial review takes place, thereby increasing the likelihood of successful deception.
One observed series of redirects begins with a Google Meet link, subsequently proceeds through Google Search, and ultimately utilizes a DoubleClick click-tracking URL. Numerous variants in the scheme utilize Google Custom Search redirects, regional Google Image Search domains, Tag Manager debug functionalities, and Google Analytics parameters. This interplay creates a complex web of URL permutations while simultaneously harnessing the credibility associated with Google’s infrastructure.
Exploiting Familiar Brands
The phishing messages often impersonate well-known brands such as DocuSign, Microsoft, OneDrive, FedEx, Intuit QuickBooks, and numerous government services. By exploiting common business workflows, the attackers are able to effectively engage recipients and elicit responses that may lead to compromised accounts.
A particularly cunning tactic involves using URL hash fragments to embed the target’s email address directly within the redirect process. In some instances, the email address is concealed using Base64 encoding. This clever maneuvering is effective because browsers typically do not transmit the fragment portion of a URL to servers, meaning that the victim’s identifier remains untraceable in server-side logs and most URL-scanning methods.
Dynamic and Personalized Phishing Pages
The final stage of the attack reveals a phishing page that decodes this information on the client side, subsequently creating a customized login interface tailored for the victim. Victims redirect through a series of Google services before ultimately reaching domains that are under the control of the attackers, including potentially compromised sites or malicious Cloudflare Workers endpoints.
According to researchers from KnowBe4 Threat Lab, the operation intelligently routes targets through an intricate maze involving Google Meet, Google Search, DoubleClick, and other trusted services before finally guiding them to attacker-controlled infrastructure. Often, victims initially see misleading interstitial messages or a fake “Human Scan Process” CAPTCHA, presumably designed to disrupt any automated security assessments.
Targeting Specific Sectors
This phishing campaign identifies and targets organizations across various sectors such as manufacturing, government, finance, and non-profit entities. By using tailored lures related to document reviews, Microsoft 365 expirations, FedEx deliveries, QuickBooks payments, Social Security notifications, and voicemail alerts, attackers enhance their chances of success.
The final phishing page is generated dynamically using the victim’s email address, enabling the attackers to pull in organizational logos from services such as Clearbit, utilize Google’s favicon service, and even display live screenshots of the target organization’s public website as a background. This personalization transforms the phishing experience from generic to highly convincing, as victims are presented with a page that closely resembles their actual corporate identity.
Monetization Tactics
The operation has developed two primary monetization strategies. The first diverts targets to Microsoft sign-in pages or fraudulent OneDrive portals, seeking to capture passwords or intercept authorization flows. The collected credentials are sent to an attacker-controlled Telegram bot, which includes the victim’s IP address, geographic location, browser details, and MX-record status.
Additionally, attackers may provoke a second password submission by generating an “Invalid password” error after the initial attempt. This allows them to capture credentials twice while creating a plausible reason for the victim’s second submission.
The second monetization path employs fake prompts for document access or identity verification to deploy ScreenConnect. This legitimate tool allows attackers to maintain interactive access to the compromised device, providing a more persistent foothold that can survive password resets and effectively sidestep multi-factor authentication protections.
Recommendations for Defenders
Given the intricacies involved in this phishing scheme, security teams should no longer consider Google-hosted links as inherently safe. It is vital for defenders to conduct thorough inspections of complete redirect chains and raise alerts on any unusual Google redirect parameters. Furthermore, organizations should be vigilant in investigating unauthorized installations of ScreenConnect, particularly those disconnected from legitimate IT workflows.
Indicators of compromise (IOCs) related to this operation, which include various malicious domains, can serve as valuable resources for organizations seeking to safeguard themselves. Security teams are encouraged to block identified IOCs across DNS, proxy, and SIEM frameworks. Additionally, it would be prudent to examine users who have received corresponding lures and to reset potentially compromised credentials.
Overall, the sophistication and personalization of this phishing scheme emphasize the need for heightened awareness and proactive measures against such evolving cyber threats.

