Threat actors are abusing legitimate Google services to conceal phishing campaigns designed to steal corporate credentials and, in some cases, install remote-access software. The campaign uses Google-owned domains as trusted intermediaries before redirecting victims to attacker-controlled pages. Phishing messages imitate routine workplace notifications, including document reviews, mailbox expiration warnings, package deliveries, payment requests, voicemail alerts, and government benefit communications. Targets reportedly include organizations in manufacturing, government, financial services, and nonprofit sectors. KnowBe4 Threat Lab researchers identified multiple redirect chains involving services such as Google Meet, Google Search, DoubleClick, Custom Search, Image Search, Tag Manager, and Analytics. Attackers also place the victim’s email address after the URL fragment symbol and may encode it using Base64. Because browsers do not normally send URL fragments to web servers, this technique can reduce the exposure of targeting information in server logs and certain scanning systems. The phishing infrastructure performs browser, location, and domain checks before displaying customized login pages. These pages can include the victim organization’s branding, website imagery, browser language, and prefilled email address, making the fraudulent request appear more credible. Submitted credentials can be forwarded to an attacker-controlled Telegram bot along with technical information. The phishing kit may deliberately reject the first password and request another entry, increasing the likelihood of collecting multiple credentials. A separate attack path presents a fake verification process that installs ScreenConnect, a legitimate remote-management application that can provide attackers with persistent workstation access when misused. Organizations should reset credentials exposed through phishing, identify unauthorized ScreenConnect installations, block malicious indicators at DNS and proxy layers, monitor suspicious Telegram Bot API activity, and report abusive redirect infrastructure through appropriate security channels.
A new Linux malware bot named Tengu has been identified as a stealthy threat capable of turning compromised Linux servers, embedded systems, and IoT-adjacent devices into DDoS atta...
The Linux kernel development team has officially ended support for the Linux Kernel 7.1 branch, meaning it will no longer receive security patches, bug fixes, or maintenance update...
Threat actors are abusing legitimate Google services to conceal phishing campaigns designed to steal corporate credentials and, in some cases, install remote-access software. The c...