Google Services Abused in Sophisticated Phishing Campaign
Cyber attackers have devised a sophisticated phishing campaign that uses trusted Google services to conceal their credential-stealing tactics. The scheme, discovered by KnowBe4 Threat Lab analysts, leverages Google-owned domains as a trust proxy to bypass automated defenses and deceive users.
The malicious emails are crafted to mimic familiar workplace themes, such as document reviews, expiring mailboxes, package deliveries, payment notices, voicemail alerts, and government benefits. They target staff across various industries, including manufacturing, government, finance, and non-profit organizations.
Once a user clicks on the link, they are led through a series of legitimate Google endpoints before reaching an attacker-controlled page. The campaign's blend of trusted links, personalized pages, and scanner checks makes it challenging for ordinary users and automated defenses to detect.