Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access.
Attackers Use Multi-Hop Google Redirects for Phishing Campaign
Phishing crews are chaining together trusted Google services as redirect hops, which lets malicious links slip past filters and reputation checks that treat google.com domains as safe. The payoff is credential theft or installation of ScreenConnect for persistent remote access, a common precursor to ransomware or fraud. It's a reminder that domain reputation alone is a weak signal for both security tools and end users.
- Attackers are using multi-hop redirects across legitimate Google services to evade email and URL security filters.
- End goals include harvesting credentials and deploying ScreenConnect for remote access.
- Trusted-domain reputation is no longer reliable defense; final destinations need inspection.
YubiKey 5C NFC Security Key — Phishing campaigns like this one exist to steal passwords and login codes, and a hardware security key is the strongest defense because it won't authenticate to a fake domain. The YubiKey 5C NFC works over USB-C and taps against a phone via NFC, so you can lock down Google, Microsoft, and password manager accounts on every device you use.
See YubiKey 5C NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.