Attackers Use Multi-Hop Google Redirects for Phishing Campaign

A new phishing campaign has been identified that leverages multiple Google services to bypass security filters and evade detection. Threat actors are utilizing a multi-hop redirection technique, chaining various Google-hosted services to lead unsuspecting users toward malicious landing pages. The primary objective of these campaigns is to harvest sensitive user credentials or to deploy ScreenConnect, a remote access tool that grants attackers unauthorized control over the victim's machine. By abusing legitimate, trusted domains, the attackers successfully increase the click-through rate and circumvent traditional email security gateways that often whitelist Google-owned infrastructure. Security researchers warn that this technique highlights a growing trend of 'living off the land' within cloud ecosystems, where adversaries exploit trusted platforms to facilitate their malicious activities. Organizations are advised to implement robust endpoint protection and user awareness training to mitigate the risks associated with these sophisticated, redirect-based social engineering attacks.
This is a summary. Read the full article at the original source:
Dark ReadingRelated stories
Security researchers and tech reviewers from Gamers Nexus and Level1Techs have raised concerns regarding the privacy practices of LG televisions. Inve…
Microsoft has released its largest-ever patch bundle, addressing at least 974 security vulnerabilities across its Windows operating systems and softwa…
Microsoft's latest Patch Tuesday update has reached a staggering new record, addressing 974 Common Vulnerabilities and Exposures (CVEs). This massive…



