Bypassing the Gatekeepers: How a Global Phishing Campaign Turns Google's Infrastructure into a Trust Proxy
Cybercriminals are exploiting legitimate Google infrastructure in a sophisticated phishing operation that bypasses email security gateways and enterprise firewalls. The attack chains together six distinct Google properties including Meet, Search, DoubleClick, Custom Search, Tag Manager and Analytics to proxy malicious traffic through trusted domains. Victims' email addresses are encoded in URL fragments and stripped before server-side logging. Landing pages dynamically impersonate target organizations by pulling live logos from Clearbit, capturing real-time website screenshots, and validating domains via Google's DNS API. The operation includes multilingual support for 16 languages and dual execution tracks: credential harvesting with immediate Telegram exfiltration, or silent ScreenConnect remote access tool installation. Lures span document reviews, credential expiry notices, package delivery, payment notifications, government benefits and voicemail themes targeting manufacturing, government, finance and...
Pulse ID: 6a9ef40735b49c55dc7166c9
Pulse Link: https://otx.alienvault.com/pulse/6a9ef40735b49c55dc7166c9
Pulse Author: AlienVault
Created: 2026-09-07 17:27:35
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CredentialHarvesting #CyberSecurity #DNS #DoubleClick #Email #Google #Government #ICS #InfoSec #Manufacturing #OTX #OpenThreatExchange #Phishing #Proxy #RAT #Rust #ScreenConnect #Telegram #bot #AlienVault
#doubleclick
1 posts · Last used 29d
You've seen all posts