Hackers Abuse Trusted Google Services to Hide Credential-Stealing Phishing Attacks
Brief
Criminals are using trusted Google services as cover for a wide phishing campaign that steals corporate credentials and, in some cases, installs remote-access software. The malicious path runs through Google-owned domains before reaching attacker-controlled pages for users and filters.
The emails use familiar workplace themes, including document reviews, expiring mailboxes, package deliveries, payment notices, voicemail alerts and government benefits. The lures target staff across manufacturing, government, finance and non-profit organizations.
KnowBe4 Threat Lab analysts identified the activity as an effort to turn trusted web infrastructure into a trust proxy.
KnowBe4 said in a report shared with Cyber Security News (CSN) that victims can be led either to credential-harvesting pages or to a fake verification flow that installs ScreenConnect.
