Attackers Use Multi-Hop Google Redirects for Phishing Campaign
Attackers are using a sophisticated multi-hop redirection technique leveraging multiple Google services to bypass security filters and deliver targeted phishing attacks. The campaign involves a complex chain of redirects, ultimately leading to credential harvesting or the installation of remote access tools like ScreenConnect, with a focus on masking the pre-targeted nature of the attacks.
A new phishing campaign is utilizing a complex multi-hop redirection scheme across various Google services to evade security measures and deliver targeted attacks. Cybersecurity vendor KnowBe4 published research on September 4th detailing this ongoing campaign. The core tactic involves chaining together services like Google Meet, DoubleClick ad infrastructure, Google Custom Search, Google Image Search, Google Tag Manager, and Google Analytics to create a lengthy redirect sequence.
This method allows the malicious link to pass through email gateways and security tools, as the gateway is fed a series of legitimate Google domains at each hop. The final destination is a phishing landing page where attackers either harvest credentials from a fake corporate login page or install ScreenConnect, a remote access tool, via a deceptive identity verification prompt.
The campaign is highly targeted, with email addresses encoded in base64 and hidden within the URL fragment, making them invisible to server-side logs and most URL scanners. Researchers observed a diverse range of lures, including document review requests, credential expiry notifications, package delivery alerts, government benefit information, and voicemail prompts.
Once a victim enters their credentials, they are immediately delivered to the attacker's Telegram channel, along with additional information such as the victim's IP address, geolocation, browser string, and verified MX records for their organization. To mitigate the threat, KnowBe4 recommends blocking IOCs at DNS filter, proxy, and SIEM levels, hunting for Telegram bot API traffic, forcing credential resets for potentially affected users, and monitoring for unauthorized ScreenConnect installations. Google did not respond to Dark Reading's request for comment.
