LmCast :: Stay tuned in

Attackers Use Multi-Hop Google Redirects for Phishing Campaign

Recorded: Sept. 8, 2026, 10:01 p.m.

Original Summarized

Attackers Use Multi-Hop Google Redirects for Phishing Informa TechTarget|SearchSecurityCybersecurity DiveInformationWeekChannel DiveExplore our brandsAn Informa TechTarget PublicationDark Reading Resource LibraryBlack Hat NewsOmdia CybersecurityAdvertiseNewsletter Sign-UpNewsletter Sign-UpCybersecurity TopicsRelated TopicsApplication SecurityCybersecurity CareersCloud SecurityCyber RiskCyberattacks & Data BreachesCybersecurity AnalyticsCybersecurity OperationsData PrivacyEndpoint SecurityICS/OT SecurityIdentity & Access Mgmt SecurityInsider ThreatsIoTMobile SecurityPerimeterPhysical SecurityRemote WorkforceThreat IntelligenceVulnerabilities & ThreatsRecent in Cybersecurity TopicsVulnerabilities & ThreatsPatch Tuesday Sets Another Record With 974 CVEsPatch Tuesday Sets Another Record With 974 CVEsbyJai VijayanSep 8, 20265 Min ReadVulnerabilities & ThreatsAI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?byAlexander CulafiSep 4, 20265 Min ReadWorld Related TopicsDR GlobalAsia PacificEuropeLatin AmericaMiddle East & AfricaSee AllThe EdgeDR TechnologyEventsRelated TopicsUpcoming EventsPodcastsWebinarsSEE ALLResourcesRelated TopicsResource LibraryWhite PapersReportsWebinarsNewslettersPodcastsHeard It From a CISOReporters' NotebookDark Reading's 20thVideosDark Reading PollsPartner PerspectivesMeet the EditorsAdvertise With Us About UsDark Reading Resource LibraryCyberattacks & Data BreachesData PrivacyThreat IntelligenceRemote WorkforceNewsAttackers Use Multi-Hop Google Redirects for Phishing CampaignThreat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access.Alexander Culafi,Senior News Writer,Dark ReadingSeptember 8, 20263 Min ReadSource: LeoPatrizi via Getty ImagesAttackers are chaining together multiple Google services in order to get phishing links past security gateways.Cybersecurity vendor KnowBe4 published research on Sept. 4 concerning an ongoing phishing campaign observed in the wild. To some extent, the mechanics of the campaign are typical: The threat actor sends a malicious email under false pretenses, the victim clicks the link, and the link leads to a malicious landing page where the victim is compromised.What sets this campaign apart is the link in the initial phishing email. In order to bypass gateways, email filters, and other security tools, the link relies on a chain of redirects across Google domains, intending for link inspectors to see multiple Google domains and let the URL through.Attackers regularly lean on redirects through legitimate infrastructure and have for years, but this method stands out because the threat campaign deliberately uses multiple Google services within the redirection chain. KnowBe4 threat analysts Prabhakaran Ravichandhiran and Jeewan Singh Jalal described a three-hop redirect chain that uses services including Google Meet, DoubleClick ad infrastructure, Google Custom Search, Google Image Search, Google Tag Manager, and Google Analytics.Related:OpenAI Agents Took Over Wiki Site Before Hugging Face Attack"By the time a defender inspects the sending domain, the embedded link, or the intermediate hops, everything still looks clean. The harvester at the end of the chain is built to wait for that inspection to pass," the blog post read. "Most phishing campaigns embed a malicious link and bet on the gateway missing it. This one does not need the gateway to miss anything. It feeds the gateway exactly what it expects: trusted Google domains at every hop."Using Google Infrastructure in Targeted AttacksAt the end of the chain, the URL redirects to a phishing landing page. In some instances, KnowBe4 observed credential harvesting from a fake corporate login page. In others, a script installs ScreenConnect as a remote access tool via a fake identity verification prompt.Notably, once the victim clicks a phishing link, the landing page's JavaScript dynamically constructs a credential harvesting landing page from the victim's email address alone, displaying a live screenshot of the victim's corporate website behind the login page. There is also a multilingual UI, which localizes the victim's session to their location.As far as lures go, KnowBe4 says the campaign does not adhere to one single type but rather a range of business contexts. Researchers saw document review, credential expiry, package delivery, payment notification, government benefit, and voicemail lures. Once the victim's credentials are entered, they're delivered to the operator's Telegram channel within seconds along with other information including "the victim's IP address, geolocation, browser string and verified MX records for their organization."Related:Large Enterprises Targeted in Fake Merger & Acquisition ScamsThe campaign appears to be targeted rather than indiscriminate, based on how the phishing URLs are constructed. "Victim email addresses are encoded in base64 and hidden in the URL hash fragment, which browsers strip before sending any request, making it invisible to server-side logs and most URL scanners, effectively masking the pre-targeted nature of the campaign," the blog post read.KnowBe4's research includes indicators of compromise (IOCs) as well as recommendations to block the IOCs at the DNS filter, proxy, and SIEM level now; hunt for Telegram bot API traffic; force credential resets for users that may have received lures associated with this campaign; hunt for unauthorized ScreenConnect installations or activity; and alert users to the URL fragment technique."An email address in the URL after # is a signal the link is pre-targeted," the threat analysts wrote.Google did not respond to Dark Reading's request for comment.Related:What the AI Warning Letter Completely MissedAbout the AuthorAlexander CulafiSenior News Writer, Dark ReadingAlex is an award-winning writer, journalist, and podcast host based in Boston. After cutting his teeth writing for independent gaming publications as a teenager, he graduated from Emerson College in 2016 with a Bachelor of Science in journalism. He has previously been published on VentureFizz, Search Security, Nintendo World Report, and elsewhere.At Dark Reading, he covers a variety of cybersecurity topics, including the cybercrime ecosystem, open source security, and the intersection between AI and threat actors. In his spare time, Alex hosts the weekly Nintendo podcast, "Talk Nintendo Podcast," and works on personal writing projects, including two previously self-published science fiction novels.He has received numerous awards, including TechTarget's Writer of the Year in 2022 as well as more than 10 Azbee awards for his reporting between 2022 and today.See more from Alexander CulafiWant more Dark Reading stories in your Google search results?Add Us NowMore InsightsIndustry ReportsThe State of Cloud Security: The Latest ChallengesHow Organizations Are Managing Incident ResponseHow Enterprises Are Developing Secure ApplicationsInside RSAC 2026: security leaders reveal the risks redefining your defense strategyEssential News & Insights from Black Hat USA 2025Access More ResearchWebinarsBenchmark Scores Are a False FlagThreat Exposure Analytics: Measuring and Communicating Security RiskBuilding an Effective Red Team: Beyond Penetration TestingHow to Leverage Threat Intelligence Without Drowning: The Zero Noise ApproachCloud Incident Response: Forensics in Distributed EnvironmentsMore WebinarsFeaturedCheck out the Black Hat USA 2026 Conference Guide for coverage and intel from — and about — the show!Editor's ChoiceCyber RiskWhat We Missed: Delta Flight Disrupted With Wi-Fi HackWhat We Missed: Delta Flight Disrupted With Wi-Fi HackbyRob Wright,Alexander CulafiAug 20, 2026Cyberattacks & Data BreachesAgentic AI Presents New Insider Threat Model for OrgsAgentic AI Presents New Insider Threat Model for OrgsAug 19, 2026Want more Dark Reading stories in your Google search results?How Organizations Are Managing Incident ResponseNearly every organization faced a critical security incident last year, but most weren't equipped to contain it. Get the full findings in this free report.Download NowNovember 12, 2026 | VIRTUALWhat Every Enterprise Should Know About Securing Cloud Assets In the Age of AISave Your SpotKeep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.SubscribeDiscover MoreBlack HatOmdiaWorking With UsAbout UsMeet the EditorsAdvertiseReprintsJoin UsNewsletter Sign-UpFollow UsCopyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466.Home|Cookie Policy|Privacy|Terms of UseYour Privacy Choices

Threat actors are leveraging a sophisticated method involving multi-hop redirects across legitimate Google services to execute phishing campaigns, effectively evading security gateways and detection systems. The core mechanism relies on chaining together various Google domains in a redirection sequence, which presents a deceptive appearance to link inspectors by presenting only trusted Google infrastructure at each step. This technique allows the malicious link to bypass email filters and other security tools because the threat actor ensures that every intermediate hop consists of recognized Google domains, feeding the security gateway exactly what it expects: legitimate traffic.

This chaining process involves utilizing a specific set of services in the redirection chain, including Google Meet, DoubleClick ad infrastructure, Google Custom Search, Google Image Search, Google Tag Manager, and Google Analytics. This multi-hop structure ensures that even when analyzing the sending domain or intermediate links, security tools cannot adequately inspect the full path until the malicious destination is reached. The objective of this maneuver is to ensure that link inspectors fail to detect the malicious intent embedded within the chain itself.

Upon successfully routing the victim, the final destination is a phishing landing page designed for compromise. This platform is utilized in various ways; in some instances, attackers harvest credentials from fraudulent corporate login pages, while in others, scripts are used to install remote access tools like ScreenConnect through deceptive identity verification prompts. The dynamic nature of the landing page further enhances its effectiveness, as its JavaScript code constructs credential harvesting forms directly from the victim's email address and displays live screenshots of the corresponding corporate website behind the fake login interface. Furthermore, the landing page incorporates a multilingual user interface to localize the session according to the victim's geographic location, further tailoring the compromise experience.

The lures used by these campaigns are diverse, ranging from requests for document review, payment notifications, package delivery updates, government benefits, and voicemail alerts. Once credentials are provided, the information is rapidly delivered to the operator via channels such as Telegram, alongside valuable data points such as the victim's IP address, geolocation, browser string, and verified MX records for their organization.

The campaign exhibits a targeted nature based on how the phishing URLs are constructed. Threat analysts observed that victim email addresses are encoded using base64 and concealed within the URL hash fragment. Because browsers typically strip content following the hash symbol before sending requests, this method effectively masks the pre-targeted nature of the attack from server-side logs and most traditional URL scanners. Consequently, an email address appearing after a hash symbol signals that the link is pre-targeted and intended to evade scrutiny.

To mitigate these advanced attacks, researchers recommend implementing several defensive measures. These include deploying systems to block indicators of compromise at the DNS filter, proxy, and SIEM levels. Furthermore, defenders must actively hunt for illicit Telegram bot API traffic and unauthorized ScreenConnect installations or activity. It is also crucial to enforce credential resets for any users associated with lures from such campaigns and to educate users about recognizing the URL fragment technique as a potential indicator.