logo

GTFire Phishing Scheme Abuses Google Services to Evade Detection and Steal Credentials

ID: 624eac60-4e4d-5834-9a6f-cc9b30b9f84a

STIX ID: report--624eac60-4e4d-5834-9a6f-cc9b30b9f84a

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-02

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

GTFire is a global phishing campaign that leverages Google Translate as a relay and Firebase-hosted *.web.app subdomains to deliver convincing brand-impersonation login pages; victims’ credentials are captured (Base64-encoded) and sent to PHP-based All-in-1.php C2 servers before users are redirected to the real sites. Group-IB’s analysis uncovered thousands of stolen credentials spanning over 1,000 organizations in 100+ countries, highlighted over 120 phishing domains and reusable phishing templates, and recommends enforcing phishing-resistant MFA, creating detections for translate.goog + *.web.app patterns, monitoring cloud-hosted brand impersonation, and sharing IOCs with CERTs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.