Phishers Leverage Google Redirect Chain to Evade Detection
A sophisticated phishing campaign has been observed by cybersecurity vendor KnowBe4, using a unique technique to bypass security gateways. The attackers are chaining multiple Google services together in a redirect chain, making it difficult for defenders to detect the malicious link.
The threat actors are sending emails with links that appear to come from trusted sources, but upon closer inspection, the URL is revealed to be a series of redirects across various Google domains. This allows the attackers to evade detection by security tools and gateways.
Once the victim clicks on the link, they are taken to a phishing landing page where their credentials can be harvested. The campaign has been observed using a range of lures, including document review, credential expiry, package delivery, payment notification, government benefit, and voicemail notifications.
The researchers at KnowBe4 have identified indicators of compromise (IOCs) and are recommending that organizations block these IOCs at the DNS filter, proxy, and SIEM level. They also advise hunting for Telegram bot API traffic and forcing credential resets for users who may have received lures associated with this campaign.