logo

GTFire Phishing Scheme: Avoiding Detection Using Google Services

ID: cf8495e6-c60f-5e09-bd61-3e48c1f3e5a9

STIX ID: report--cf8495e6-c60f-5e09-bd61-3e48c1f3e5a9

Feed Name: Group-IB Blog

Threat Score
75/100

Date Published: 2026-02-26

Date Updated: 2026-04-28

...
...

GTFire is a global credential-harvesting phishing campaign that weaponizes Google Firebase hosting and Google Translate redirect/proxying to hide malicious pages and evade security controls; Group-IB observed thousands of stolen credentials across 1,000+ organizations in 100+ countries, detailed redirect flows, exfiltration via All-in-1.php (Base64-encoded GET requests), victimology, IOCs (e.g., *.web.app + translate.goog, jnhwzs.fyi, gnpnia.lat), and recommended mitigations such as phishing-resistant MFA and monitoring for brand impersonation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.