Executive Summary
In September 2026, cybersecurity researchers at KnowBe4 identified a sophisticated phishing campaign exploiting multiple Google services to evade detection systems. Threat actors chained together Google Meet, DoubleClick, Google Custom Search, and other Google infrastructure to create multi-hop redirect sequences that appear legitimate to security gateways. The campaign dynamically constructs credential harvesting pages based on victim email addresses and deploys ScreenConnect remote access tools through fake identity verification prompts. Victims' stolen credentials are delivered to operators via Telegram channels within seconds, along with IP addresses, geolocation data, and organizational details.
This incident highlights the evolving sophistication of phishing attacks that abuse trusted infrastructure to bypass traditional security controls. As threat actors increasingly leverage legitimate cloud services for malicious purposes, organizations face growing challenges in detecting attacks that appear benign at every inspection point until the final malicious payload is delivered.
Why This Matters Now
This campaign represents a critical shift in phishing sophistication, demonstrating how attackers exploit trusted cloud infrastructure to completely bypass traditional email security. With the technique actively bypassing reputation-based filtering and MFA protections, organizations need immediate updates to their detection capabilities.
Attack Path Analysis
Attackers initiated a sophisticated phishing campaign using multi-hop Google redirects to bypass security gateways, leading victims to credential harvesting pages or ScreenConnect remote access tool installation. The campaign leveraged trusted Google domains across multiple services to evade detection, dynamically constructed targeted landing pages, and established persistent remote access for potential lateral movement and data exfiltration.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Threat actors sent targeted phishing emails with malicious links that chain through multiple Google services (Meet, DoubleClick, Custom Search, Tag Manager) to bypass email gateways and security filters, ultimately redirecting to credential harvesting pages or ScreenConnect installation prompts
MITRE ATT&CK® Techniques
Phishing: Spearphishing Link
User Execution: Malicious Link
Masquerading: Match Legitimate Name or Location
Proxy: Multi-hop Proxy
Process Injection: Process Hollowing
Input Capture: Keylogging
Remote Access Software
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Security Awareness Program
Control ID: 12.6.1
NYDFS 23 NYCRR 500 – Training and Monitoring
Control ID: 500.14
DORA – ICT Risk Management Framework
Control ID: Article 13
CISA ZTMM 2.0 – Phishing-Resistant MFA
Control ID: Identity - Advanced
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21.2(a)
ISO 27001:2022 – Information Transfer Policies
Control ID: A.13.2.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Multi-hop Google redirect phishing campaigns targeting credential harvesting pose severe risks to financial institutions through compromised customer accounts and regulatory compliance violations.
Information Technology/IT
IT organizations face elevated risks from sophisticated phishing leveraging trusted Google infrastructure, potentially compromising client systems through ScreenConnect remote access tool installations.
Health Care / Life Sciences
Healthcare sector vulnerable to targeted phishing campaigns using corporate login spoofing, risking HIPAA violations and patient data exposure through credential theft.
Government Administration
Government entities targeted by multilingual phishing campaigns using document review and benefit lures, creating national security risks through compromised administrative credentials.
Sources
- Attackers Use Multi-Hop Google Redirects for Phishing Campaignhttps://www.darkreading.com/cyberattacks-data-breaches/attackers-multi-hop-google-redirects-phishing-campaignVerified
- KnowBe4 Research on Multi-Hop Google Redirect Phishing Campaignhttps://www.knowbe4.com/blogVerified
- CISA Phishing Guidance and Best Practiceshttps://www.cisa.gov/topics/cybersecurity-best-practices/phishing-guidanceVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain this multi-stage phishing attack by limiting egress paths for credential exfiltration and restricting lateral movement through microsegmented networks. The segmentation controls could reduce blast radius and contain attacker reach across cloud environments.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: CNSF visibility controls would likely provide enhanced detection capabilities for suspicious redirection patterns and unauthorized software installation attempts across cloud workloads and network traffic flows.
Control: Zero Trust Segmentation
Mitigation: Zero Trust segmentation would likely constrain privilege escalation by enforcing identity-based access controls and limiting the scope of compromised credentials to specific network segments and resource boundaries.
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely limit lateral movement by inspecting and restricting inter-workload communications, reducing attacker reachability across cloud environments and sensitive system boundaries.
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility controls would likely detect and constrain command and control communications by monitoring traffic patterns and identifying unauthorized external connections across diverse cloud environments and platforms.
Control: Egress Security & Policy Enforcement
Mitigation: Egress security controls would likely constrain data exfiltration by blocking or limiting outbound communications to unauthorized external services and restricting the volume of sensitive information leaving the network perimeter.
Segmentation controls would likely reduce overall business impact by containing compromised resources within isolated network boundaries and limiting attacker access to critical systems and sensitive data repositories.
Impact at a Glance
Affected Business Functions
- Corporate Authentication Systems
- Email Communications
- Remote Access Infrastructure
- Identity Verification Processes
Estimated downtime: 3 days
Estimated loss: $75,000
Employee credentials including usernames and passwords, corporate login information, IP addresses, geolocation data, browser fingerprints, and organizational MX records transmitted to threat actors via Telegram channels within seconds of credential entry.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Cloud Firewall (ACF) with URL filtering and egress control to block malicious redirect chains and unauthorized outbound communications to services like Telegram
- • Deploy Multicloud Visibility & Control to detect anomalous interactions with multiple Google services and suspicious automation patterns in redirect chains
- • Establish Egress Security & Policy Enforcement to prevent unauthorized data exfiltration and block access to known command and control infrastructure
- • Enable Cloud Native Security Fabric (CNSF) with real-time inspection to identify and block phishing campaigns that abuse legitimate cloud services for malicious redirects
- • Implement Threat Detection & Anomaly Response capabilities to baseline normal user behavior and alert on suspicious remote access tool installations like ScreenConnect



