As cited
Copy frozen at (site build).
threat intel
Attackers Use Multi-Hop Google Redirects for Phishing Campaign
Threat actors are exploiting multiple Google services through a redirect chain to bypass security controls in phishing campaigns. The attacks culminate in credential theft or installation of ScreenConnect for remote access.
Why it matters: Organizations relying on URL reputation filtering need to monitor for multi-hop redirects through legitimate Google domains, as this technique obfuscates malicious endpoints and increases successful compromise rates.
- Source published
- First seen by Cybersecurity Tracker