Threat reportPhishingTL-2026-2372

Global Credential-Stealing Phishing Campaign Abusing Trusted Google Services as Redirect Infrastructure

highACTIVE

Global Credential-Stealing Phishing Campaign Abusing Trusted (TL-2026-2372), also tracked as Bypassing the Gatekeepers, is a high-severity phishing campaign, first published 2026-09-07. It has no confirmed attribution, affects Google Google Meet, maps to 17 MITRE ATT&CK techniques (T1027, T1056.003, T1059.001), and is covered by 9 detection rules and 28 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
17MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
28Indicators of compromise

Key facts for TL-2026-2372

Threat ID
TL-2026-2372
Also known as
Bypassing the Gatekeepers
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
manufacturing, government administration, finance, non-profit organisation, health, education
Target regions
North America, Europe
Detection rules
9
Indicators of compromise
28

Malware and tooling in Global Credential-Stealing Phishing Campaign Abusing Trusted

Malware and tooling: ScreenConnect

How Global Credential-Stealing Phishing Campaign Abusing Trusted works

KnowBe4 Threat Lab reports an active global phishing campaign that abuses six legitimate Google-owned services (Google Meet, Search, DoubleClick, Custom Search, Image Search, Tag Manager, Analytics) as open redirect proxies to bypass email security filters. The campaign targets manufacturing, government, finance, and non-profit organizations across North America and Europe, using personalized landing pages that dynamically pull victim organization logos and screenshots, and a two-stage attack chain delivering either credential harvesting via Telegram bot exfiltration or ScreenConnect remote access via a fake identity-verification prompt.

KnowBe4 Threat Lab has identified a sophisticated, active global phishing campaign that systematically routes victims through chains of legitimate Google-owned open redirect endpoints before landing on attacker-controlled credential-harvesting or remote-access pages. The campaign, documented in a September 4, 2026 analysis titled 'Bypassing the Gatekeepers,' abuses up to six distinct Google services across multiple redirect paths: Google Meet (meet.google.com/linkredirect with unrestricted dest= parameter), Google Search (www.google.com/url?q=), Google DoubleClick (adservice.google.com.ph/ddm/clk/ with a valid gclid= parameter), Google Custom Search Engine (cse.google.com/url), Google Image Search regional ccTLD variants (images.google.com.bd, images.google.com.dj), Google Tag Manager (googletagmanager.com/debug/clearcookies), and Google Analytics (analytics.google.com with dl= parameter). The redirect chains create a 'trust proxy' effect: every hop lands on a legitimate Google domain, assigning clean reputation scores at each step and making the malicious destination invisible to secure email gateways until a human clicks through. The campaign does not require the gateway to miss anything — it feeds the gateway exactly what it expects: trusted Google domains at every hop. Emails pass SPF, DKIM, and DMARC authentication because there is nothing technically wrong with the message delivery itself.

The campaign implements a dual-track post-redirect architecture. Track A delivers a high-fidelity Microsoft 365 sign-in page or a OneDrive device-code phishing portal that captures credentials. The victim arrives with their email already pre-filled in the login field, extracted from a base64-encoded value in the URL hash fragment — a fragment invisible to browser-server request headers and thus invisible to server-side logs and most URL scanners. The first submission always returns a deliberate 'Invalid password' error regardless of input, prompting the victim to re-enter their password. The second submission confirms the credential pair and exfiltrates both along with IP address, geolocation, browser string, and verified MX records to a Telegram bot via the Telegram Bot API. The page then redirects the victim to their real company website with no indication of compromise. Track B routes victims through document-access or identity-verification lures to a fabricated 'Identity Verification Required' prompt that silently drops and executes a script installing ScreenConnect, a legitimate remote monitoring and management (RMM) tool. Once ScreenConnect establishes a session, the operator gains persistent, interactive access to the victim's machine that persists through password resets and is not disrupted by MFA.

Before serving any malicious content, the phishing kit performs extensive victim profiling and anti-analysis checks. Using JavaScript, the kit queries ipinfo.io for IP geolocation (city, region, country), validates the victim's email domain via Google Public DNS MX record queries (dns.google/resolve), and pulls the victim organization's logo live from Clearbit with a Google favicon fallback. A real-time screenshot of the victim's organization website is rendered as the page background via a third-party screenshot API. The page dynamically sets its browser tab title to the victim's organization name, mimics the organization's branding, and localizes the interface into 16 languages based on browser locale, including English, Chinese, Japanese, Portuguese, Korean, Spanish, Italian, German, French, Lithuanian, Swedish, Estonian, Turkish, Arabic, Russian, and Vietnamese. Automated sandboxes are filtered through a fake CAPTCHA ('Human Scan Process'), an interstitial checkpoint on .vu domains that drops non-interactive visitors, and MX record validation that flags researcher/sandbox domains. The campaign has been active since at least July 2026, with related infrastructure documented by multiple security vendors across the year. Attacker infrastructure spans .vu ccTLD domains, Cloudflare Workers endpoints, compromised .de, .cz, .pt, .tr subdomains, and a compromised SharePoint tenant used as a redirect hop. No specific threat actor has been attributed to the campaign.

Email lures span a wide variety of workplace themes including document review notifications (impersonating DocuSign, SafeSend ONE), credential expiry warnings (Microsoft 365, Office 365), package delivery notices (FedEx Express using a compromised Brazilian university domain), payment notifications (OneDrive, Intuit QuickBooks with embedded QR codes for mobile recipients), government benefit notifications (Social Security), and Microsoft voicemail alerts. The campaign has been observed targeting hundreds of organizations across the U.S., Canada, and Europe, with confirmed sector targeting in manufacturing, government, finance, non-profit, healthcare, and education. The dynamic personalization and localization make this campaign unusually difficult to detect through automated analysis alone, and remediation requires a combination of credential resets, ScreenConnect hunting, DNS/proxy IOC blocking, and expanded Google redirect monitoring beyond Meet and Search to include all six abused services.

MITRE ATT&CK techniques used in TL-2026-2372

Defense Evasion

T1027 Obfuscated Files or Information; T1497 Virtualization/Sandbox Evasion; T1684.001 Impersonation

Credential Access

T1056.003 Input Capture: Web Portal Capture

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1059.007 Command and Scripting Interpreter: JavaScript; T1204.001 User Execution: Malicious Link

Command and Control

T1219 Remote Access Tools

Initial Access

T1566.002 Phishing: Spearphishing Link

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1583.001 Acquire Infrastructure: Domains; T1583.006 Acquire Infrastructure: Web Services; T1584.001 Compromise Infrastructure: Domains; T1584.006 Compromise Infrastructure: Web Services; T1608.005 Stage Capabilities: Link Target

Reconnaissance

T1589.002 Gather Victim Identity Information: Email Addresses; T1590.001 Gather Victim Network Information: Domain Properties

Affected products and versions in Global Credential-Stealing Phishing Campaign Abusing Trusted

  • Google — Google Meet
    Vulnerable versions: All deployments with /linkredirect endpoint active
  • Google — Google Search
    Vulnerable versions: All deployments with /url?q= open redirect
  • Google — Google DoubleClick
    Vulnerable versions: All deployments with /ddm/clk/ click tracking endpoint
  • Google — Google Custom Search Engine
    Vulnerable versions: All deployments with /url?q= open redirect
  • Google — Google Tag Manager
    Vulnerable versions: All deployments with /debug/clearcookies debug endpoint
  • Google — Google Analytics
    Vulnerable versions: All deployments with dl= parameter redirect
  • Microsoft — Microsoft 365
    Vulnerable versions: All deployments — authentication pages impersonated
  • ConnectWise — ScreenConnect
    Vulnerable versions: All versions — abused as legitimate RMM tool for remote access

Remediation for Global Credential-Stealing Phishing Campaign Abusing Trusted

Immediate actions

  • Block all known IOC domains at DNS filter, proxy, and SIEM immediately
  • Force credential resets for any users who may have received these lures
  • Hunt for unauthorized ScreenConnect installations across the enterprise — any ScreenConnect process outside known administrative deployments is a compromise indicator
  • Alert users: an email address appearing in a URL after the # symbol signals a pre-targeted phishing link

Workarounds

  • Report abusive redirect URLs to Google Safe Browsing to accelerate takedown of Google-hosted redirect endpoints
  • Monitor for outbound api.telegram.org/bot connections from corporate endpoints as a credential-exfiltration indicator

Longer-term hardening

  • Expand Google redirect blocking beyond Meet and Search to include googletagmanager.com/debug/clearcookies, analytics.google.com with dl= parameters, and images.google.com regional ccTLD redirect endpoints
  • Consider blocking logo.clearbit.com and image.thum.io at the web proxy, as legitimate corporate use cases are limited
  • Deploy contextual mismatch detection for email authentication — trusted senders using unexpected services or destinations
  • Implement behavioral detection for Telegram Bot API outbound traffic (api.telegram.org/bot)

Timeline of Global Credential-Stealing Phishing Campaign Abusing Trusted

  • Hornet Security publishes analysis of Google Meet open redirect being abused for phishing, documenting early evidence of the technique being weaponized in the wild
  • Paubox reports on attackers abusing Google services to hide phishing links from security tools, documenting the growing trend of Google infrastructure abuse
  • ThreatCluster first observes the campaign infrastructure active in the wild, with the Google open redirect chain and credential-harvester infrastructure becoming operational
  • ThreatCluster formally documents the campaign cluster with IOCs, redirect chain analysis, and confirmed targeting of hundreds of organizations across the U.S., Canada, and Europe
  • IronScales publishes analysis of the campaign's HTML attachment variant using Google Meet open redirect with base64-encoded recipient email in URL fragment, detailing the MX record validation and anti-sandbox measures
  • KnowBe4 Threat Lab publishes 'Bypassing the Gatekeepers' analysis detailing the full campaign architecture: six Google services abused, dual-track delivery (credential harvesting via Telegram + ScreenConnect RAT), 16-language localization, and comprehensive IOC list
  • Campaign threat intelligence published to the Threadlinqs Intelligence Platform; campaign remains active with ongoing targeting of manufacturing, government, finance, and non-profit sectors

Sources cited for Global Credential-Stealing Phishing Campaign Abusing Trusted

Detection coverage for TL-2026-2372

As of 2026-09-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2372 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
28 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-2372

25 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats