GTFire Phishing Scheme Abuses Google Services to Evade Detection and Steal Credentials
ID: 624eac60-4e4d-5834-9a6f-cc9b30b9f84a
STIX ID: report--624eac60-4e4d-5834-9a6f-cc9b30b9f84a
Feed Name: cybersecurityNews.com
GTFire is a global phishing campaign that leverages Google Translate as a relay and Firebase-hosted *.web.app subdomains to deliver convincing brand-impersonation login pages; victims’ credentials are captured (Base64-encoded) and sent to PHP-based All-in-1.php C2 servers before users are redirected to the real sites. Group-IB’s analysis uncovered thousands of stolen credentials spanning over 1,000 organizations in 100+ countries, highlighted over 120 phishing domains and reusable phishing templates, and recommends enforcing phishing-resistant MFA, creating detections for translate.goog + *.web.app patterns, monitoring cloud-hosted brand impersonation, and sharing IOCs with CERTs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
