Hackers Abuse Trusted Google Services to Hide Credential-Stealing Phishing Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Criminals are using trusted Google services as cover for a wide phishing campaign that steals corporate credentials and, in some cases, installs remote-access software. The malicious path runs through Google-owned domains before reaching attacker-controlled pages for users and filters.

The emails use familiar workplace themes, including document reviews, expiring mailboxes, package deliveries, payment notices, voicemail alerts and government benefits. The lures target staff across manufacturing, government, finance and non-profit organizations.

KnowBe4 Threat Lab analysts identified the activity as an effort to turn trusted web infrastructure into a trust proxy.

KnowBe4 said in a report shared with Cyber Security News (CSN) that victims can be led either to credential-harvesting pages or to a fake verification flow that installs ScreenConnect.

The impact is more than a stolen password. A successful login theft can open email, cloud files and internal services, while an unauthorized remote-access session can give an intruder continuing control of a workstation.

Abuse of Google services (Source - Knowbe4)
Abuse of Google services (Source – Knowbe4)

The blend of trusted links, personalized pages and scanner checks makes the campaign harder for ordinary users and automated defenses to spot.

Hackers Abuse Trusted Google Services

Rather than placing an obvious phishing address in an email, the operators send recipients through a series of legitimate Google endpoints.

Observed routes include Google Meet, Google Search, DoubleClick, Custom Search, Image Search, Tag Manager and Analytics, with some chains using several services before leaving Google infrastructure.

A related case involving Google service phishing abuse shows why familiar sender and web domains can add credibility to fraudulent messages. One route starts with Google Meet, moves through Google Search and then DoubleClick click tracking.

Other variants use a Google Custom Search redirect, regional Google Image Search domains, Tag Manager’s debug endpoint, or an Analytics parameter. Each stage looks normal to tools relying on domain reputation.

The campaign also hides a target’s email address after the # symbol in a link, sometimes encoded in base64. Browsers do not send that fragment to web servers, which reduces its visibility in server logs and many URL-scanning systems.

That detail lets the final page know who is arriving while keeping the personalized targeting data out of much of the redirect trail.

An example package delivery lure (Source - Knowbe4)
An example package delivery lure (Source – Knowbe4)

This echoes Google OAuth phishing flaws, where authentic Google infrastructure can make a harmful message appear safer than it is. A trusted intermediate domain is not proof that the final destination, request or download deserves trust.

Personalized Pages and Remote Access

After the last redirect, the phishing kit checks the visitor before showing a login form. It can collect location and browser details, verify that the email domain has working mail records, and present fake human-verification screens.

These checks can screen out automated analysis tools and make the operation more selective. The final page is tailored from the email address.

It can retrieve the target organization’s logo, place a live screenshot of its website behind the form, prefill the recipient’s email address, and display text in the browser’s language. That makes a fake sign-in request more convincing.

When a victim submits a password, the kit sends the data to a Telegram bot along with technical details. It then deliberately reports an invalid password and asks for another entry, a tactic that can capture a second credential pair before redirecting the person to their real company website.

Readers can compare this pattern with the fake invitation phishing campaign, which also used a false password error to draw out another submission.

A separate route poses as identity verification but silently installs ScreenConnect, a legitimate remote-management tool that attackers can misuse for persistent access.

Organizations should reset credentials for exposed users, look for unauthorized ScreenConnect installations, block known indicators at DNS and proxy layers, watch for Telegram Bot API traffic, and report abusive redirect URLs to Google Safe Browsing.

Recent ScreenConnect malware delivery attacks underline how trusted remote-support tools can turn a single click into a wider incident.

Indicators of compromise (IoCs):-

Type Indicator Description
Domain vazquezfleytas[.]com Credential harvester
Domain zh-l-haixing[.]com Credential harvester
Domain odahlzr5lm[.]reliabilityinoperations[.]de Credential harvester
Domain cloudbemismanufacturingcompanygroup[.]rydezyhrsysteminc[.]vu Credential harvester
Domain servicetriumphgroupsimplyappraisals[.]spectrhwqumbrands[.]vu Credential harvester
Domain unitedtechnofzmlogies[.]vu Credential harvester
Domain velvorra[.]com Credential harvester
Domain cloudgillettebrandberkshirehathaway[.]rtzcoekdrporation[.]vu Credential harvester
Domain furqanmustafa[.]com Credential harvester / infrastructure
Domain staiwooje[.]app Credential harvester
Domain edificiocristal[.]pt Infrastructure
Cloudflare Worker Link-form-unj9[.]p-sm7rw6ru[.]workers[.]dev Credential harvester
Cloudflare Worker data-cloud-ofe8[.]p-8yejy42o[.]workers[.]dev Credential harvester
Telegram Chat ID 7861974506 C2 exfiltration
Domain goldenearth[.]ma Credential harvester
Domain document24acces[.]com Credential harvester
Domain anglictina-doucovani[.]cz Infrastructure
Domain camara-verde[.]org Infrastructure
Domain demo[.]mybluekart[.]com Credential harvester
Domain sefvraa[.]com Credential harvester
Domain guzeldagenerji[.]com[.]tr Infrastructure
Domain monntgro[.]com Credential harvester
Domain cindymagee[.]net Credential harvester
Domain itunes321[.]rovitan[.]vu Credential harvester
Domain servicesmallplanetdigitalsystems[.]gdipbrinfotech[.]vu Credential harvester
Domain pittni[.]com Credential harvester
SharePoint tenant amzn-redirecturl-dc73bfyf29-campaign[.]sharepoint[.]com Redirect infrastructure

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

The post Hackers Abuse Trusted Google Services to Hide Credential-Stealing Phishing Attacks appeared first on Cyber Security News.