Criminals are using trusted Google services as cover for a wide phishing campaign that steals corporate credentials and, in some cases, installs remote-access software. The malicious path runs through Google-owned domains before reaching attacker-controlled pages for users and filters.
The emails use familiar workplace themes, including document reviews, expiring mailboxes, package deliveries, payment notices, voicemail alerts and government benefits. The lures target staff across manufacturing, government, finance and non-profit organizations.
KnowBe4 Threat Lab analysts identified the activity as an effort to turn trusted web infrastructure into a trust proxy.
KnowBe4 said in a report shared with Cyber Security News (CSN) that victims can be led either to credential-harvesting pages or to a fake verification flow that installs ScreenConnect.
The impact is more than a stolen password. A successful login theft can open email, cloud files and internal services, while an unauthorized remote-access session can give an intruder continuing control of a workstation.

The blend of trusted links, personalized pages and scanner checks makes the campaign harder for ordinary users and automated defenses to spot.
Hackers Abuse Trusted Google Services
Rather than placing an obvious phishing address in an email, the operators send recipients through a series of legitimate Google endpoints.
Observed routes include Google Meet, Google Search, DoubleClick, Custom Search, Image Search, Tag Manager and Analytics, with some chains using several services before leaving Google infrastructure.
A related case involving Google service phishing abuse shows why familiar sender and web domains can add credibility to fraudulent messages. One route starts with Google Meet, moves through Google Search and then DoubleClick click tracking.
Other variants use a Google Custom Search redirect, regional Google Image Search domains, Tag Manager’s debug endpoint, or an Analytics parameter. Each stage looks normal to tools relying on domain reputation.
The campaign also hides a target’s email address after the # symbol in a link, sometimes encoded in base64. Browsers do not send that fragment to web servers, which reduces its visibility in server logs and many URL-scanning systems.
That detail lets the final page know who is arriving while keeping the personalized targeting data out of much of the redirect trail.

This echoes Google OAuth phishing flaws, where authentic Google infrastructure can make a harmful message appear safer than it is. A trusted intermediate domain is not proof that the final destination, request or download deserves trust.
Personalized Pages and Remote Access
After the last redirect, the phishing kit checks the visitor before showing a login form. It can collect location and browser details, verify that the email domain has working mail records, and present fake human-verification screens.
These checks can screen out automated analysis tools and make the operation more selective. The final page is tailored from the email address.
It can retrieve the target organization’s logo, place a live screenshot of its website behind the form, prefill the recipient’s email address, and display text in the browser’s language. That makes a fake sign-in request more convincing.
When a victim submits a password, the kit sends the data to a Telegram bot along with technical details. It then deliberately reports an invalid password and asks for another entry, a tactic that can capture a second credential pair before redirecting the person to their real company website.
Readers can compare this pattern with the fake invitation phishing campaign, which also used a false password error to draw out another submission.
A separate route poses as identity verification but silently installs ScreenConnect, a legitimate remote-management tool that attackers can misuse for persistent access.
Organizations should reset credentials for exposed users, look for unauthorized ScreenConnect installations, block known indicators at DNS and proxy layers, watch for Telegram Bot API traffic, and report abusive redirect URLs to Google Safe Browsing.
Recent ScreenConnect malware delivery attacks underline how trusted remote-support tools can turn a single click into a wider incident.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Domain | vazquezfleytas[.]com |
Credential harvester |
| Domain | zh-l-haixing[.]com |
Credential harvester |
| Domain | odahlzr5lm[.]reliabilityinoperations[.]de |
Credential harvester |
| Domain | cloudbemismanufacturingcompanygroup[.]rydezyhrsysteminc[.]vu |
Credential harvester |
| Domain | servicetriumphgroupsimplyappraisals[.]spectrhwqumbrands[.]vu |
Credential harvester |
| Domain | unitedtechnofzmlogies[.]vu |
Credential harvester |
| Domain | velvorra[.]com |
Credential harvester |
| Domain | cloudgillettebrandberkshirehathaway[.]rtzcoekdrporation[.]vu |
Credential harvester |
| Domain | furqanmustafa[.]com |
Credential harvester / infrastructure |
| Domain | staiwooje[.]app |
Credential harvester |
| Domain | edificiocristal[.]pt |
Infrastructure |
| Cloudflare Worker | Link-form-unj9[.]p-sm7rw6ru[.]workers[.]dev |
Credential harvester |
| Cloudflare Worker | data-cloud-ofe8[.]p-8yejy42o[.]workers[.]dev |
Credential harvester |
| Telegram Chat ID | 7861974506 |
C2 exfiltration |
| Domain | goldenearth[.]ma |
Credential harvester |
| Domain | document24acces[.]com |
Credential harvester |
| Domain | anglictina-doucovani[.]cz |
Infrastructure |
| Domain | camara-verde[.]org |
Infrastructure |
| Domain | demo[.]mybluekart[.]com |
Credential harvester |
| Domain | sefvraa[.]com |
Credential harvester |
| Domain | guzeldagenerji[.]com[.]tr |
Infrastructure |
| Domain | monntgro[.]com |
Credential harvester |
| Domain | cindymagee[.]net |
Credential harvester |
| Domain | itunes321[.]rovitan[.]vu |
Credential harvester |
| Domain | servicesmallplanetdigitalsystems[.]gdipbrinfotech[.]vu |
Credential harvester |
| Domain | pittni[.]com |
Credential harvester |
| SharePoint tenant | amzn-redirecturl-dc73bfyf29-campaign[.]sharepoint[.]com |
Redirect infrastructure |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.
The post Hackers Abuse Trusted Google Services to Hide Credential-Stealing Phishing Attacks appeared first on Cyber Security News.
