Phishers Exploit Multi‑Hop Google Redirects to Deploy Credential‑Stealing and Remote‑Access Malware
Security researchers have identified a new phishing operation that chains together several Google redirects to conceal malicious links, enabling attackers to harvest user credentials or silently install the ScreenConnect remote‑access application.
The scheme begins with a seemingly innocuous URL that points to a Google service such as Docs or Drive. That link then forwards to another Google address before finally landing on a counterfeit login page or a download prompt for the remote‑access tool. Each hop appears to originate from a trusted domain, making traditional URL‑filtering solutions less effective.
Victims who follow the full redirect chain are presented with a replica of a legitimate sign‑in portal, where entered usernames and passwords are captured, or they are prompted to run a ScreenConnect installer that grants the threat actor full control of the compromised system. Once installed, the tool provides persistent, encrypted access that can be used for further data exfiltration or lateral movement within a network.
Phishing continues to rank among the most prevalent cyber threats, and the use of reputable domains like google.com is a well‑known evasion tactic. While multi‑hop redirects have been observed in earlier campaigns, this operation distinguishes itself by systematically employing a sequence of Google services to mask the final destination, a detail highlighted in a recent Dark Reading report.
Experts advise organizations to enhance their defenses by inspecting full redirect chains rather than relying on the initial domain, tightening email gateway filters, and educating users to hover over links and verify URLs before clicking. Deploying endpoint protection capable of detecting unauthorized ScreenConnect binaries can also reduce the risk of compromise.
As defenders adapt their detection rules, attackers are likely to explore alternative trusted platforms or shorten the redirect chain to stay ahead of security controls. Ongoing monitoring of redirect abuse and rapid sharing of indicators of compromise remain critical to mitigating this evolving phishing technique.
Comments (0)
Be the first to comment.
Join the discussion