Executive Summary

In September 2026, cybersecurity researchers at KnowBe4 identified a sophisticated phishing campaign exploiting multiple Google services to evade detection systems. Threat actors chained together Google Meet, DoubleClick, Google Custom Search, and other Google infrastructure to create multi-hop redirect sequences that appear legitimate to security gateways. The campaign dynamically constructs credential harvesting pages based on victim email addresses and deploys ScreenConnect remote access tools through fake identity verification prompts. Victims' stolen credentials are delivered to operators via Telegram channels within seconds, along with IP addresses, geolocation data, and organizational details.

This incident highlights the evolving sophistication of phishing attacks that abuse trusted infrastructure to bypass traditional security controls. As threat actors increasingly leverage legitimate cloud services for malicious purposes, organizations face growing challenges in detecting attacks that appear benign at every inspection point until the final malicious payload is delivered.

Why This Matters Now

This campaign represents a critical shift in phishing sophistication, demonstrating how attackers exploit trusted cloud infrastructure to completely bypass traditional email security. With the technique actively bypassing reputation-based filtering and MFA protections, organizations need immediate updates to their detection capabilities.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The attack chains multiple legitimate Google services together, so security tools only see trusted Google domains at each inspection point, allowing malicious URLs to pass through undetected.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely constrain this multi-stage phishing attack by limiting egress paths for credential exfiltration and restricting lateral movement through microsegmented networks. The segmentation controls could reduce blast radius and contain attacker reach across cloud environments.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: CNSF visibility controls would likely provide enhanced detection capabilities for suspicious redirection patterns and unauthorized software installation attempts across cloud workloads and network traffic flows.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero Trust segmentation would likely constrain privilege escalation by enforcing identity-based access controls and limiting the scope of compromised credentials to specific network segments and resource boundaries.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic controls would likely limit lateral movement by inspecting and restricting inter-workload communications, reducing attacker reachability across cloud environments and sensitive system boundaries.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud visibility controls would likely detect and constrain command and control communications by monitoring traffic patterns and identifying unauthorized external connections across diverse cloud environments and platforms.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress security controls would likely constrain data exfiltration by blocking or limiting outbound communications to unauthorized external services and restricting the volume of sensitive information leaving the network perimeter.

Impact (Mitigations)

Segmentation controls would likely reduce overall business impact by containing compromised resources within isolated network boundaries and limiting attacker access to critical systems and sensitive data repositories.

Impact at a Glance

Affected Business Functions

  • Corporate Authentication Systems
  • Email Communications
  • Remote Access Infrastructure
  • Identity Verification Processes
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $75,000

Data Exposure

Employee credentials including usernames and passwords, corporate login information, IP addresses, geolocation data, browser fingerprints, and organizational MX records transmitted to threat actors via Telegram channels within seconds of credential entry.

Recommended Actions

  • Implement Cloud Firewall (ACF) with URL filtering and egress control to block malicious redirect chains and unauthorized outbound communications to services like Telegram
  • Deploy Multicloud Visibility & Control to detect anomalous interactions with multiple Google services and suspicious automation patterns in redirect chains
  • Establish Egress Security & Policy Enforcement to prevent unauthorized data exfiltration and block access to known command and control infrastructure
  • Enable Cloud Native Security Fabric (CNSF) with real-time inspection to identify and block phishing campaigns that abuse legitimate cloud services for malicious redirects
  • Implement Threat Detection & Anomaly Response capabilities to baseline normal user behavior and alert on suspicious remote access tool installations like ScreenConnect

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image