RESEARCHERS from KnowBe4 Threat Lab have detailed a sophisticated phishing operation that exploits Google infrastructure to harvest credentials and deploy a remote access tool. The campaign is notable for routing the user through trusted Google domains at multiple stages, meaning traditional security gateways often fail to block it.
The attackers use a multi-hop redirect chain that traverses Google Meet, Google Custom Search, DoubleClick, and Google Tag Manager, before presenting a customised, convincing login page. Victim email addresses are embedded in the URL hash fragment as base64, a technique browsers do not send to servers, making the data hard to log or scan.
There are two parallel tracks in the attack. In the credential-harvesting track, the system deliberately rejects the first password submission with an “Invalid password” message, prompting a second entry by the user and yielding a high-confidence credential pair, which is then exfiltrated via a Telegram bot. In the second track, a fake identity verification screen quietly installs ConnectWise ScreenConnect, granting persistent remote access to the corporate endpoint and bypassing multi-factor authentication.
The threat actor is as yet unattributed, though the level of sophistication points to a well-organised cybercrime operation targeting organisations across manufacturing, finance, government and NGOs in 16 languages.
Defence recommendations emphasise adapting beyond simple domain blocking: educate users to scrutinise the final landing page URL and deploy endpoint monitoring for silent remote-access tool installations. The report underscores the need to analyse complete redirect chains and to monitor URL fragments, not just initial links. UK date: 11 September 2026.