TechNewsReel
Live

Phishing Campaign Abuses Google Service Chain to Bypass Security Gateways

Attackers route victims through trusted Google domains to evade URL scanners and harvest corporate credentials.

TechNewsReel Newsroom · September 8, 2026

Threat actors are deploying a sophisticated phishing campaign that leverages a chain of legitimate Google services to slip past enterprise security gateways. By routing victims through multiple high-reputation domains, the attackers turn Google's own infrastructure into a trust proxy to deliver malicious payloads.

The attack utilizes a multi-hop redirect chain that bounces users across various services, including Google Meet, DoubleClick, Google Custom Search, Google Image Search, Google Tag Manager, and Google Analytics. Once the chain is complete, victims are directed to a final destination: either a dynamic credential harvesting page or a prompt to install ScreenConnect for unauthorized remote access. To further evade detection, attackers encode victim email addresses in base64 and place them within the URL hash fragment (#), a technique that renders the targeting data invisible to most URL scanners and server-side logs.

The Trust Proxy Strategy

While open redirects have been a staple of phishing for years, this campaign is distinct in its systematic use of a "trust proxy" approach. Most enterprise security layers are configured to whitelist or lightly scrutinize traffic from Google infrastructure due to the ubiquity of its services. By chaining several of these properties together, the attackers ensure that each hop in the journey appears legitimate to automated defense systems.

According to the KnowBe4 Threat Lab, this method changes the fundamental nature of the evasion. "Most phishing campaigns embed a malicious link and bet on the gateway missing it," the lab stated. "This one does not need the gateway to miss anything. It feeds the gateway exactly what it expects: trusted Google domains at every hop."

Implications for Enterprise Defense

This technique effectively neutralizes many traditional email security gateways and URL detonation platforms. Because these tools are designed to flag suspicious or unknown domains, they are often blind to a sequence of redirects that only touch verified, high-reputation assets.

Furthermore, the use of URL fragments for victim tracking creates a significant blind spot for defenders. Because fragments are handled by the browser and not sent to the server, standard web logs do not capture the encoded email addresses. This makes it exceptionally difficult for security teams to determine the full scope of a campaign or identify exactly which users were targeted.

What to Watch

Defenders should monitor for unusual redirect patterns involving multiple Google properties and educate users on the risks of installing remote access software like ScreenConnect from unsolicited links. As attackers continue to weaponize trusted cloud ecosystems, the industry may need to shift away from domain-based whitelisting toward more rigorous behavioral analysis of the entire redirect chain.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.