Attackers Use Multi-Hop Google Redirects for Phishing Campaign
Summary
Threat actors are employing a sophisticated phishing campaign that leverages multiple Google services, including Google Redirects, to bypass security measures and deliver their malicious payloads. The ultimate goals of this campaign are credential harvesting or the installation of the ScreenConnect remote access tool.
IFF Assessment
Attackers are finding new ways to circumvent security controls and deliver malware, posing a direct threat to organizations.
Defender Context
This campaign highlights the evolving tactics of threat actors who are increasingly abusing legitimate cloud services to hide their malicious activities. Defenders should be vigilant about monitoring for unusual redirect chains and look for indicators of compromise related to credential theft and the deployment of remote access tools.