Google Services Used as Cover for Sophisticated Phishing Campaign
Cybersecurity experts have identified a wide-ranging phishing campaign that utilizes trusted Google services to conceal its malicious intent. The campaign, which targets employees across various industries including manufacturing, government, finance, and non-profit organizations, aims to steal corporate credentials and install remote-access software.
The attackers employ a complex network of legitimate Google domains to disguise their phishing kit's activities. They use familiar workplace themes in the emails sent to victims, such as document reviews, expiring mailboxes, package deliveries, payment notices, voicemail alerts, and government benefits. The lures are designed to be convincing, making it challenging for ordinary users and automated defenses to detect.
The phishing kit checks the visitor's details before showing a login form, collecting location and browser information, verifying that the email domain has working mail records, and presenting fake human-verification screens. The final page is tailored from the email address, displaying the target organization's logo, a live screenshot of its website, prefilling the recipient's email address, and displaying text in the browser's language.
When a victim submits their password, the kit sends the data to a Telegram bot along with technical details. The attackers then deliberately report an invalid password and ask for another entry, capturing a second credential pair before redirecting the person to their real company website.