logo

Bypassing the Gatekeepers: How a Global Phishing Campaign Turns Google's Infrastructure into a Trust Proxy

ID: 70d0b972-9ffe-505a-81a9-182e21e93ba8

STIX ID: report--70d0b972-9ffe-505a-81a9-182e21e93ba8

Feed Name: KnowBe4 Blog

Threat Score
78/100

Date Published: 2026-09-04

Date Updated: 2026-09-05

Author: KnowBe4 Threat Lab

...
...

This KnowBe4 Threat Lab analysis describes an active, wide-scale targeted phishing campaign that chains multiple legitimate Google services (meet.google.com, www.google.com/url, adservice/DoubleClick, cse.google.com, images.google.*, googletagmanager.com, analytics.google.com) to bypass security controls and redirect victims to attacker infrastructure; the harvester dynamically personalizes pages using the victim's email (from the URL fragment), fetches live company logos and screenshots, validates MX records via Google Public DNS, exfiltrates credentials to a Telegram bot, and in some cases delivers ScreenConnect for persistent remote access—reporting multiple lure themes, extensive profiling/anti-analysis checks, a table of IOCs (domains, Cloudflare Workers, a Telegram chat ID, compromised SharePoint tenant), and recommended mitigations such as blocking IOCs, hunting for Telegram API traffic, forcing resets, and monitoring for unauthorized ScreenConnect installations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.