Bypassing the Gatekeepers: How a Global Phishing Campaign Turns Google's Infrastructure into a Trust Proxy
Cybercriminals are exploiting legitimate Google infrastructure in a sophisticated phishing operation that bypasses email security gateways and enterprise firewalls. The attack chains together six distinct Google properties including Meet, Search, DoubleClick, Custom Search, Tag Manager and Analytics to proxy malicious traffic through trusted domains. Victims' email addresses are encoded in URL fragments and stripped before server-side logging. Landing pages dynamically impersonate target organizations by pulling live logos from Clearbit, capturing real-time website screenshots, and validating domains via Google's DNS API. The operation includes multilingual support for 16 languages and dual execution tracks: credential harvesting with immediate Telegram exfiltration, or silent ScreenConnect remote access tool installation. Lures span document reviews, credential expiry notices, package delivery, payment notifications, government benefits and voicemail themes targeting manufacturing, government, finance and...
AI Analysis
Technical Summary
This sophisticated phishing campaign chains together six Google properties—Meet, Search, DoubleClick, Custom Search, Tag Manager, and Analytics—to proxy malicious traffic through trusted Google domains, effectively bypassing common email and network defenses. Victims' email addresses are encoded in URL fragments to avoid server-side logging. Landing pages dynamically impersonate targeted organizations by fetching live logos from Clearbit, capturing real-time screenshots, and validating domains through Google's DNS API. The campaign supports 16 languages and employs two main attack tracks: credential harvesting with immediate exfiltration to Telegram, and silent installation of the ScreenConnect remote access tool. Lures include document reviews, credential expiry notices, package delivery, payment notifications, government benefits, and voicemail themes, targeting sectors such as manufacturing, government, and finance.
Potential Impact
The campaign enables attackers to bypass email security gateways and enterprise firewalls by leveraging trusted Google infrastructure, increasing the likelihood of successful phishing attacks. Victims risk credential compromise and unauthorized remote access through ScreenConnect installation. The use of legitimate Google domains for proxying malicious content complicates detection and blocking efforts, potentially leading to data breaches and unauthorized system access in targeted organizations.
Mitigation Recommendations
No official patch or fix applies as this is an abuse of legitimate cloud infrastructure rather than a software vulnerability. Organizations should increase user awareness about phishing tactics that leverage trusted domains and monitor for suspicious activity related to credential use and remote access tools. Email security solutions should be tuned to detect unusual URL patterns and behaviors despite the use of trusted domains. Vendors managing Google services handle infrastructure security; users must rely on layered defenses and user training.
Indicators of Compromise
- domain: company.com
- domain: furqanmustafa.com
- domain: pittni.com
- domain: vazquezfleytas.com
- domain: edificiocristal.pt
- domain: odahlzr5lm.reliabilityinoperations.de
- domain: cloudbemismanufacturingcompanygroup.rydezyhrsysteminc.vu
- domain: servicetriumphgroupsimplyappraisals.spectrhwqumbrands.vu
- domain: velvorra.com
- domain: cloudgillettebrandberkshirehathaway.rtzcoekdrporation.vu
- domain: guzeldagenerji.com.tr
- domain: anglictina-doucovani.cz
- domain: goldenearth.ma
- domain: document24acces.com
- domain: camara-verde.org
- domain: demo.mybluekart.com
- domain: sefvraa.com
- domain: monntgro.com
- domain: cindymagee.net
- domain: itunes321.rovitan.vu
- domain: servicesmallplanetdigitalsystems.gdipbrinfotech.vu
- domain: zh-l-haixing.com
- url: http://zh-l-haixing.com/drooll/
- domain: msgelement.show
Bypassing the Gatekeepers: How a Global Phishing Campaign Turns Google's Infrastructure into a Trust Proxy
Description
Cybercriminals are exploiting legitimate Google infrastructure in a sophisticated phishing operation that bypasses email security gateways and enterprise firewalls. The attack chains together six distinct Google properties including Meet, Search, DoubleClick, Custom Search, Tag Manager and Analytics to proxy malicious traffic through trusted domains. Victims' email addresses are encoded in URL fragments and stripped before server-side logging. Landing pages dynamically impersonate target organizations by pulling live logos from Clearbit, capturing real-time website screenshots, and validating domains via Google's DNS API. The operation includes multilingual support for 16 languages and dual execution tracks: credential harvesting with immediate Telegram exfiltration, or silent ScreenConnect remote access tool installation. Lures span document reviews, credential expiry notices, package delivery, payment notifications, government benefits and voicemail themes targeting manufacturing, government, finance and...
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This sophisticated phishing campaign chains together six Google properties—Meet, Search, DoubleClick, Custom Search, Tag Manager, and Analytics—to proxy malicious traffic through trusted Google domains, effectively bypassing common email and network defenses. Victims' email addresses are encoded in URL fragments to avoid server-side logging. Landing pages dynamically impersonate targeted organizations by fetching live logos from Clearbit, capturing real-time screenshots, and validating domains through Google's DNS API. The campaign supports 16 languages and employs two main attack tracks: credential harvesting with immediate exfiltration to Telegram, and silent installation of the ScreenConnect remote access tool. Lures include document reviews, credential expiry notices, package delivery, payment notifications, government benefits, and voicemail themes, targeting sectors such as manufacturing, government, and finance.
Potential Impact
The campaign enables attackers to bypass email security gateways and enterprise firewalls by leveraging trusted Google infrastructure, increasing the likelihood of successful phishing attacks. Victims risk credential compromise and unauthorized remote access through ScreenConnect installation. The use of legitimate Google domains for proxying malicious content complicates detection and blocking efforts, potentially leading to data breaches and unauthorized system access in targeted organizations.
Defensive Guidance
No official patch or fix applies as this is an abuse of legitimate cloud infrastructure rather than a software vulnerability. Organizations should increase user awareness about phishing tactics that leverage trusted domains and monitor for suspicious activity related to credential use and remote access tools. Email security solutions should be tuned to detect unusual URL patterns and behaviors despite the use of trusted domains. Vendors managing Google services handle infrastructure security; users must rely on layered defenses and user training.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://blog.knowbe4.com/bypassing-the-gatekeepers-how-a-global-phishing-campaign-turns-googles-infrastructure-into-a-trust-proxy"]
- Adversary
- null
- Pulse Id
- 6a9ef40735b49c55dc7166c9
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domaincompany.com | — | |
domainfurqanmustafa.com | — | |
domainpittni.com | — | |
domainvazquezfleytas.com | — | |
domainedificiocristal.pt | — | |
domainodahlzr5lm.reliabilityinoperations.de | — | |
domaincloudbemismanufacturingcompanygroup.rydezyhrsysteminc.vu | — | |
domainservicetriumphgroupsimplyappraisals.spectrhwqumbrands.vu | — | |
domainvelvorra.com | — | |
domaincloudgillettebrandberkshirehathaway.rtzcoekdrporation.vu | — | |
domainguzeldagenerji.com.tr | — | |
domainanglictina-doucovani.cz | — | |
domaingoldenearth.ma | — | |
domaindocument24acces.com | — | |
domaincamara-verde.org | — | |
domaindemo.mybluekart.com | — | |
domainsefvraa.com | — | |
domainmonntgro.com | — | |
domaincindymagee.net | — | |
domainitunes321.rovitan.vu | — | |
domainservicesmallplanetdigitalsystems.gdipbrinfotech.vu | — | |
domainzh-l-haixing.com | — | |
domainmsgelement.show | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://zh-l-haixing.com/drooll/ | — |
Threat ID: 6a9f9b8cacd9273b490eafea
Added to database: 09/08/2026, 05:22:20 UTC
Last enriched: 09/08/2026, 05:38:46 UTC
Last updated: 09/08/2026, 13:15:05 UTC
Views: 20
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.