Google Infrastructure Abused in Sophisticated Phishing Campaign
A sophisticated phishing campaign has been discovered that leverages Google's infrastructure to evade detection and trick corporate victims into surrendering their credentials. The attackers have developed a highly effective method of using multiple legitimate Google services as redirect intermediaries, making it nearly impossible for security systems to detect the malicious link.
The campaign, which has been observed targeting various business contexts, including manufacturing, government, finance, and non-profit organizations, uses six distinct Google properties across multiple redirect paths. The attackers have taken great care to ensure that every URL in the campaign routes through legitimate Google-owned infrastructure before hitting their own attacker infrastructure.
One of the most striking features of this campaign is its ability to dynamically impersonate a victim's organization in real-time, using Clearbit to pull live company logos and a third-party screenshot API to take screenshots of the victim's website. The attackers also use Google's public DNS to verify the victim's email domain, filtering out sandbox detonations and researcher addresses that use fake domains.
The campaign is notable for its dual-track post-redirect architecture, which delivers either credential theft or persistent remote access depending on the lure context. In addition, a separate execution track silently installs a remote access tool rather than harvesting credentials, further adding to the campaign's sophistication.