# Global Credential-Stealing Phishing Campaign Abusing Trusted Google Services as Redirect Infrastructure

> KnowBe4 Threat Lab reports an active global phishing campaign that abuses six legitimate Google-owned services (Google Meet, Search, DoubleClick, Custom Search, Image Search, Tag Manager, Analytics) as open redirect proxies to bypass email security filters. The campaign targets manufacturing, government, finance, and non-profit organizations across North America and Europe, using personalized landing pages that dynamically pull victim organization logos and screenshots, and a two-stage attack chain delivering either credential harvesting via Telegram bot exfiltration or ScreenConnect remote access via a fake identity-verification prompt.

- **Published:** 2026-09-07T00:00:00Z
- **Last reviewed:** 2026-09-07T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2372
- **ID:** TL-2026-2372
- **Severity:** HIGH
- **Category:** PHISHING
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 28 (full data via the Threadlinqs MCP server — Purple tier)

## Description

KnowBe4 Threat Lab has identified a sophisticated, active global phishing campaign that systematically routes victims through chains of legitimate Google-owned open redirect endpoints before landing on attacker-controlled credential-harvesting or remote-access pages. The campaign, documented in a September 4, 2026 analysis titled 'Bypassing the Gatekeepers,' abuses up to six distinct Google services across multiple redirect paths: Google Meet (meet.google.com/linkredirect with unrestricted dest= parameter), Google Search (www.google.com/url?q=), Google DoubleClick (adservice.google.com.ph/ddm/clk/ with a valid gclid= parameter), Google Custom Search Engine (cse.google.com/url), Google Image Search regional ccTLD variants (images.google.com.bd, images.google.com.dj), Google Tag Manager (googletagmanager.com/debug/clearcookies), and Google Analytics (analytics.google.com with dl= parameter). The redirect chains create a 'trust proxy' effect: every hop lands on a legitimate Google domain, assigning clean reputation scores at each step and making the malicious destination invisible to secure email gateways until a human clicks through. The campaign does not require the gateway to miss anything — it feeds the gateway exactly what it expects: trusted Google domains at every hop. Emails pass SPF, DKIM, and DMARC authentication because there is nothing technically wrong with the message delivery itself.

The campaign implements a dual-track post-redirect architecture. Track A delivers a high-fidelity Microsoft 365 sign-in page or a OneDrive device-code phishing portal that captures credentials. The victim arrives with their email already pre-filled in the login field, extracted from a base64-encoded value in the URL hash fragment — a fragment invisible to browser-server request headers and thus invisible to server-side logs and most URL scanners. The first submission always returns a deliberate 'Invalid password' error regardless of input, prompting the victim to re-enter their password. The second submission confirms the credential pair and exfiltrates both along with IP address, geolocation, browser string, and verified MX records to a Telegram bot via the Telegram Bot API. The page then redirects the victim to their real company website with no indication of compromise. Track B routes victims through document-access or identity-verification lures to a fabricated 'Identity Verification Required' prompt that silently drops and executes a script installing ScreenConnect, a legitimate remote monitoring and management (RMM) tool. Once ScreenConnect establishes a session, the operator gains persistent, interactive access to the victim's machine that persists through password resets and is not disrupted by MFA.

Before serving any malicious content, the phishing kit performs extensive victim profiling and anti-analysis checks. Using JavaScript, the kit queries ipinfo.io for IP geolocation (city, region, country), validates the victim's email domain via Google Public DNS MX record queries (dns.google/resolve), and pulls the victim organization's logo live from Clearbit with a Google favicon fallback. A real-time screenshot of the victim's organization website is rendered as the page background via a third-party screenshot API. The page dynamically sets its browser tab title to the victim's organization name, mimics the organization's branding, and localizes the interface into 16 languages based on browser locale, including English, Chinese, Japanese, Portuguese, Korean, Spanish, Italian, German, French, Lithuanian, Swedish, Estonian, Turkish, Arabic, Russian, and Vietnamese. Automated sandboxes are filtered through a fake CAPTCHA ('Human Scan Process'), an interstitial checkpoint on .vu domains that drops non-interactive visitors, and MX record validation that flags researcher/sandbox domains. The campaign has been active since at least July 2026, with related infrastructure documented by multiple security vendors across the year. Attacker infrastructure spans .vu ccTLD domains, Cloudflare Workers endpoints, compromised .de, .cz, .pt, .tr subdomains, and a compromised SharePoint tenant used as a redirect hop. No specific threat actor has been attributed to the campaign.

Email lures span a wide variety of workplace themes including document review notifications (impersonating DocuSign, SafeSend ONE), credential expiry warnings (Microsoft 365, Office 365), package delivery notices (FedEx Express using a compromised Brazilian university domain), payment notifications (OneDrive, Intuit QuickBooks with embedded QR codes for mobile recipients), government benefit notifications (Social Security), and Microsoft voicemail alerts. The campaign has been observed targeting hundreds of organizations across the U.S., Canada, and Europe, with confirmed sector targeting in manufacturing, government, finance, non-profit, healthcare, and education. The dynamic personalization and localization make this campaign unusually difficult to detect through automated analysis alone, and remediation requires a combination of credential resets, ScreenConnect hunting, DNS/proxy IOC blocking, and expanded Google redirect monitoring beyond Meet and Search to include all six abused services.

## MITRE ATT&CK

- T1589.002 Gather Victim Identity Information: Email Addresses
- T1590.001 Gather Victim Network Information: Domain Properties
- T1583.001 Acquire Infrastructure: Domains
- T1583.006 Acquire Infrastructure: Web Services
- T1584.001 Compromise Infrastructure: Domains
- T1584.006 Compromise Infrastructure: Web Services
- T1608.005 Stage Capabilities: Link Target
- T1566.002 Phishing: Spearphishing Link
- T1204.001 User Execution: Malicious Link
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1059.007 Command and Scripting Interpreter: JavaScript
- T1684.001 Impersonation
- T1027 Obfuscated Files or Information
- T1497 Virtualization/Sandbox Evasion
- T1056.003 Input Capture: Web Portal Capture
- T1219 Remote Access Tools
- T1567 Exfiltration Over Web Service

## Sources

- [Bypassing the Gatekeepers: How a Global Phishing Campaign Turns Google's Infrastructure into a Trust Proxy](https://blog.knowbe4.com/bypassing-the-gatekeepers-how-a-global-phishing-campaign-turns-googles-infrastructure-into-a-trust-proxy)
- [Hackers Abuse Trusted Google Services to Hide Credential-Stealing Phishing Attacks](https://cybersecuritynews.com/trusted-google-services/)
- [Hornet Security — Google Meet Phishing Campaign Analysis](https://www.hornetsecurity.com/en/blog/google-meet-phishing/)
- [Paubox — Attackers Use Google Services to Hide Phishing Links](https://www.paubox.com/blog/attackers-use-google-services-to-hide-phishing-links-from-security-tools)
- [ThreatCluster — Campaign Cluster: Google Services Abuse for Phishing](https://threatcluster.io/cluster/attackers-use-google-services-to-hide-phishing-links-from-se-670421d6)
- [IronScales — HTML Attachment Google Meet Open Redirect Base64 Recipient Fragment](https://ironscales.com/threat-intelligence/html-attachment-google-meet-open-redirect-base64-recipient-fragment)
- [RavenMail — How Attackers Are Abusing Google Cloud Infrastructure for Phishing](https://ravenmail.io/blog/phishing-using-google-infra)
- [Malwarebytes — Fake Google Meet Update Delivers ScreenConnect](https://www.malwarebytes.com/blog/threat-intel/2026/03/one-click-on-this-fake-google-meet-update-can-give-attackers-control-of-your-pc)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2372
