Google Services Used to Bypass Security Gateways in Global Phishing Campaign
A sophisticated phishing campaign has been uncovered that uses legitimate Google services to evade security gateways and steal sensitive information. The attackers use multi-hop redirect chains involving services such as Google Meet, Search, and Tag Manager to conceal their final destination.
The campaign dynamically profiles targets in real-time, impersonating their specific organization to improve conversion rates and credential theft success.
Researchers found that the attackers encode victim email addresses within URL fragments to avoid server-side logging. They also use automated profiling through IP and geolocation APIs, along with MX record verification, to identify targets and filter out security researchers and sandbox environments.