securityonline.info 11 Sept 2026, 07:13 UTC

Hackers Abuse Google Services to Steal Logins and Install RATs

Hackers Abuse Google Services to Steal Logins and Install RATs
CyberSIXT Evidence Panel Source marked as original reporting

RESEARCHERS from KnowBe4 Threat Lab have detailed a sophisticated phishing operation that exploits Google infrastructure to harvest credentials and deploy a remote access tool. The campaign is notable for routing the user through trusted Google domains at multiple stages, meaning traditional security gateways often fail to block it.

The attackers use a multi-hop redirect chain that traverses Google Meet, Google Custom Search, DoubleClick, and Google Tag Manager, before presenting a customised, convincing login page. Victim email addresses are embedded in the URL hash fragment as base64, a technique browsers do not send to servers, making the data hard to log or scan.

There are two parallel tracks in the attack. In the credential-harvesting track, the system deliberately rejects the first password submission with an “Invalid password” message, prompting a second entry by the user and yielding a high-confidence credential pair, which is then exfiltrated via a Telegram bot. In the second track, a fake identity verification screen quietly installs ConnectWise ScreenConnect, granting persistent remote access to the corporate endpoint and bypassing multi-factor authentication.

The threat actor is as yet unattributed, though the level of sophistication points to a well-organised cybercrime operation targeting organisations across manufacturing, finance, government and NGOs in 16 languages.

Defence recommendations emphasise adapting beyond simple domain blocking: educate users to scrutinise the final landing page URL and deploy endpoint monitoring for silent remote-access tool installations. The report underscores the need to analyse complete redirect chains and to monitor URL fragments, not just initial links. UK date: 11 September 2026.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline