Hackers Abuse Google Services as Trust Proxy to Steal Credentials and Deploy ScreenConnect
Brief
Threat actors are abusing trusted Google services to route phishing victims through legitimate-looking links before sending them to credential-harvesting pages or installing ScreenConnect remote-access software.
According to a KnowBe4 Threat Lab analysis, the active campaign uses Google infrastructure as a trust proxy.
Instead of placing an obvious malicious link in an email, attackers direct recipients through Google Meet, Google Search, DoubleClick, Custom Search, Image Search, Tag Manager, and Analytics services.
Security gateways, firewalls, and URL scanners often trust these Google domains, allowing the phishing chain to pass initial inspection.
The campaign targets organizations in manufacturing, government, finance, and non-profit sectors.
Attackers use document-review, Microsoft 365 expiry , FedEx delivery, OneDrive payment, government-benefit, and voicemail-themed lures.
