Threat reportPhishingTL-2026-2372
Global Credential-Stealing Phishing Campaign Abusing Trusted Google Services as Redirect Infrastructure
Global Credential-Stealing Phishing Campaign Abusing Trusted (TL-2026-2372), also tracked as Bypassing the Gatekeepers, is a high-severity phishing campaign, first published 2026-09-07. It has no confirmed attribution, affects Google Google Meet, maps to 17 MITRE ATT&CK techniques (T1027, T1056.003, T1059.001), and is covered by 9 detection rules and 28 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 17MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 28Indicators of compromise
Key facts for TL-2026-2372
- Threat ID
- TL-2026-2372
- Also known as
- Bypassing the Gatekeepers
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- manufacturing, government administration, finance, non-profit organisation, health, education
- Target regions
- North America, Europe
- Detection rules
- 9
- Indicators of compromise
- 28
Malware and tooling in Global Credential-Stealing Phishing Campaign Abusing Trusted
Malware and tooling: ScreenConnect
How Global Credential-Stealing Phishing Campaign Abusing Trusted works
KnowBe4 Threat Lab reports an active global phishing campaign that abuses six legitimate Google-owned services (Google Meet, Search, DoubleClick, Custom Search, Image Search, Tag Manager, Analytics) as open redirect proxies to bypass email security filters. The campaign targets manufacturing, government, finance, and non-profit organizations across North America and Europe, using personalized landing pages that dynamically pull victim organization logos and screenshots, and a two-stage attack chain delivering either credential harvesting via Telegram bot exfiltration or ScreenConnect remote access via a fake identity-verification prompt.
KnowBe4 Threat Lab has identified a sophisticated, active global phishing campaign that systematically routes victims through chains of legitimate Google-owned open redirect endpoints before landing on attacker-controlled credential-harvesting or remote-access pages. The campaign, documented in a September 4, 2026 analysis titled 'Bypassing the Gatekeepers,' abuses up to six distinct Google services across multiple redirect paths: Google Meet (meet.google.com/linkredirect with unrestricted dest= parameter), Google Search (www.google.com/url?q=), Google DoubleClick (adservice.google.com.ph/ddm/clk/ with a valid gclid= parameter), Google Custom Search Engine (cse.google.com/url), Google Image Search regional ccTLD variants (images.google.com.bd, images.google.com.dj), Google Tag Manager (googletagmanager.com/debug/clearcookies), and Google Analytics (analytics.google.com with dl= parameter). The redirect chains create a 'trust proxy' effect: every hop lands on a legitimate Google domain, assigning clean reputation scores at each step and making the malicious destination invisible to secure email gateways until a human clicks through. The campaign does not require the gateway to miss anything — it feeds the gateway exactly what it expects: trusted Google domains at every hop. Emails pass SPF, DKIM, and DMARC authentication because there is nothing technically wrong with the message delivery itself.
The campaign implements a dual-track post-redirect architecture. Track A delivers a high-fidelity Microsoft 365 sign-in page or a OneDrive device-code phishing portal that captures credentials. The victim arrives with their email already pre-filled in the login field, extracted from a base64-encoded value in the URL hash fragment — a fragment invisible to browser-server request headers and thus invisible to server-side logs and most URL scanners. The first submission always returns a deliberate 'Invalid password' error regardless of input, prompting the victim to re-enter their password. The second submission confirms the credential pair and exfiltrates both along with IP address, geolocation, browser string, and verified MX records to a Telegram bot via the Telegram Bot API. The page then redirects the victim to their real company website with no indication of compromise. Track B routes victims through document-access or identity-verification lures to a fabricated 'Identity Verification Required' prompt that silently drops and executes a script installing ScreenConnect, a legitimate remote monitoring and management (RMM) tool. Once ScreenConnect establishes a session, the operator gains persistent, interactive access to the victim's machine that persists through password resets and is not disrupted by MFA.
Before serving any malicious content, the phishing kit performs extensive victim profiling and anti-analysis checks. Using JavaScript, the kit queries ipinfo.io for IP geolocation (city, region, country), validates the victim's email domain via Google Public DNS MX record queries (dns.google/resolve), and pulls the victim organization's logo live from Clearbit with a Google favicon fallback. A real-time screenshot of the victim's organization website is rendered as the page background via a third-party screenshot API. The page dynamically sets its browser tab title to the victim's organization name, mimics the organization's branding, and localizes the interface into 16 languages based on browser locale, including English, Chinese, Japanese, Portuguese, Korean, Spanish, Italian, German, French, Lithuanian, Swedish, Estonian, Turkish, Arabic, Russian, and Vietnamese. Automated sandboxes are filtered through a fake CAPTCHA ('Human Scan Process'), an interstitial checkpoint on .vu domains that drops non-interactive visitors, and MX record validation that flags researcher/sandbox domains. The campaign has been active since at least July 2026, with related infrastructure documented by multiple security vendors across the year. Attacker infrastructure spans .vu ccTLD domains, Cloudflare Workers endpoints, compromised .de, .cz, .pt, .tr subdomains, and a compromised SharePoint tenant used as a redirect hop. No specific threat actor has been attributed to the campaign.
Email lures span a wide variety of workplace themes including document review notifications (impersonating DocuSign, SafeSend ONE), credential expiry warnings (Microsoft 365, Office 365), package delivery notices (FedEx Express using a compromised Brazilian university domain), payment notifications (OneDrive, Intuit QuickBooks with embedded QR codes for mobile recipients), government benefit notifications (Social Security), and Microsoft voicemail alerts. The campaign has been observed targeting hundreds of organizations across the U.S., Canada, and Europe, with confirmed sector targeting in manufacturing, government, finance, non-profit, healthcare, and education. The dynamic personalization and localization make this campaign unusually difficult to detect through automated analysis alone, and remediation requires a combination of credential resets, ScreenConnect hunting, DNS/proxy IOC blocking, and expanded Google redirect monitoring beyond Meet and Search to include all six abused services.
MITRE ATT&CK techniques used in TL-2026-2372
Defense Evasion
T1027 Obfuscated Files or Information; T1497 Virtualization/Sandbox Evasion; T1684.001 Impersonation
Credential Access
T1056.003 Input Capture: Web Portal Capture
Execution
T1059.001 Command and Scripting Interpreter: PowerShell; T1059.007 Command and Scripting Interpreter: JavaScript; T1204.001 User Execution: Malicious Link
Command and Control
Initial Access
T1566.002 Phishing: Spearphishing Link
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
T1583.001 Acquire Infrastructure: Domains; T1583.006 Acquire Infrastructure: Web Services; T1584.001 Compromise Infrastructure: Domains; T1584.006 Compromise Infrastructure: Web Services; T1608.005 Stage Capabilities: Link Target
Reconnaissance
T1589.002 Gather Victim Identity Information: Email Addresses; T1590.001 Gather Victim Network Information: Domain Properties
Affected products and versions in Global Credential-Stealing Phishing Campaign Abusing Trusted
- Google — Google Meet
Vulnerable versions: All deployments with /linkredirect endpoint active - Google — Google Search
Vulnerable versions: All deployments with /url?q= open redirect - Google — Google DoubleClick
Vulnerable versions: All deployments with /ddm/clk/ click tracking endpoint - Google — Google Custom Search Engine
Vulnerable versions: All deployments with /url?q= open redirect - Google — Google Tag Manager
Vulnerable versions: All deployments with /debug/clearcookies debug endpoint - Google — Google Analytics
Vulnerable versions: All deployments with dl= parameter redirect - Microsoft — Microsoft 365
Vulnerable versions: All deployments — authentication pages impersonated - ConnectWise — ScreenConnect
Vulnerable versions: All versions — abused as legitimate RMM tool for remote access
Remediation for Global Credential-Stealing Phishing Campaign Abusing Trusted
Immediate actions
- Block all known IOC domains at DNS filter, proxy, and SIEM immediately
- Force credential resets for any users who may have received these lures
- Hunt for unauthorized ScreenConnect installations across the enterprise — any ScreenConnect process outside known administrative deployments is a compromise indicator
- Alert users: an email address appearing in a URL after the # symbol signals a pre-targeted phishing link
Workarounds
- Report abusive redirect URLs to Google Safe Browsing to accelerate takedown of Google-hosted redirect endpoints
- Monitor for outbound api.telegram.org/bot connections from corporate endpoints as a credential-exfiltration indicator
Longer-term hardening
- Expand Google redirect blocking beyond Meet and Search to include googletagmanager.com/debug/clearcookies, analytics.google.com with dl= parameters, and images.google.com regional ccTLD redirect endpoints
- Consider blocking logo.clearbit.com and image.thum.io at the web proxy, as legitimate corporate use cases are limited
- Deploy contextual mismatch detection for email authentication — trusted senders using unexpected services or destinations
- Implement behavioral detection for Telegram Bot API outbound traffic (api.telegram.org/bot)
Timeline of Global Credential-Stealing Phishing Campaign Abusing Trusted
- Hornet Security publishes analysis of Google Meet open redirect being abused for phishing, documenting early evidence of the technique being weaponized in the wild
- Paubox reports on attackers abusing Google services to hide phishing links from security tools, documenting the growing trend of Google infrastructure abuse
- ThreatCluster first observes the campaign infrastructure active in the wild, with the Google open redirect chain and credential-harvester infrastructure becoming operational
- ThreatCluster formally documents the campaign cluster with IOCs, redirect chain analysis, and confirmed targeting of hundreds of organizations across the U.S., Canada, and Europe
- IronScales publishes analysis of the campaign's HTML attachment variant using Google Meet open redirect with base64-encoded recipient email in URL fragment, detailing the MX record validation and anti-sandbox measures
- KnowBe4 Threat Lab publishes 'Bypassing the Gatekeepers' analysis detailing the full campaign architecture: six Google services abused, dual-track delivery (credential harvesting via Telegram + ScreenConnect RAT), 16-language localization, and comprehensive IOC list
- Campaign threat intelligence published to the Threadlinqs Intelligence Platform; campaign remains active with ongoing targeting of manufacturing, government, finance, and non-profit sectors
Sources cited for Global Credential-Stealing Phishing Campaign Abusing Trusted
- Bypassing the Gatekeepers: How a Global Phishing Campaign Turns Google's Infrastructure into a Trust Proxy
- Hackers Abuse Trusted Google Services to Hide Credential-Stealing Phishing Attacks
- Hornet Security — Google Meet Phishing Campaign Analysis
- Paubox — Attackers Use Google Services to Hide Phishing Links
- ThreatCluster — Campaign Cluster: Google Services Abuse for Phishing
- IronScales — HTML Attachment Google Meet Open Redirect Base64 Recipient Fragment
- RavenMail — How Attackers Are Abusing Google Cloud Infrastructure for Phishing
- Malwarebytes — Fake Google Meet Update Delivers ScreenConnect
Detection coverage for TL-2026-2372
As of 2026-09-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2372 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-2372
25 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.