{"id":416536,"date":"2026-09-19T05:15:40","date_gmt":"2026-09-19T05:15:40","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=416536"},"modified":"2026-09-19T05:15:40","modified_gmt":"2026-09-19T05:15:40","slug":"google-redirect-phishing-trusted-links","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/google-redirect-phishing-trusted-links\/","title":{"rendered":"Google Redirect Phishing Uses Trusted Links to Steal Logins"},"content":{"rendered":"<p>An email says a document needs approval, a mailbox will expire, a package was missed, or a payment is waiting. The embedded link begins on a genuine Google domain, so the usual advice to inspect the address appears to confirm that it is safe.<\/p><div id=\"mwtad2461765020\" class=\"gas_fallback-ad_309684--placement_406659\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>Several trusted Google services may appear as the browser moves from one page to the next.<\/p>\n<p>The Google addresses are real. The trust created by them is what the phishing campaign is designed to borrow.<\/p><div id=\"mwtad3315328997\" class=\"gas_fallback-ad_381396-ad_309685-placement_406667\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"675\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" alt=\"Business phishing email with Google link used in the Google Redirect Phishing Uses Trusted Links to Steal Logins investigation\" class=\"wp-image-416537 lazyload\" title=\"\" sizes=\"auto, (max-width: 1200px) 100vw, 1200px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/google-redirect-phishing-trusted-links-1-final.png\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/google-redirect-phishing-trusted-links-1-final.png 1200w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/google-redirect-phishing-trusted-links-1-final-300x169.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/google-redirect-phishing-trusted-links-1-final-1024x576.png 1024w\"><\/figure>\n<div id=\"mwtad1801770113\" class=\"gas_fallback-ad_309746-ad_309685-placement_406660\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<h3>The phishing link deliberately passes through Google infrastructure<\/h3>\n<p>KnowBe4 researchers documented an active, wide-scale phishing campaign that routes victims through legitimate Google services before reaching attacker-controlled pages. The operation abused six Google properties across several redirect paths, including Google Meet, Search, DoubleClick, Custom Search, Image Search, Tag Manager, and Analytics-related endpoints.<\/p>\n<p>Google itself is not sending the phishing email or operating the final page. The criminals misuse redirect and tracking functions that normally help users leave meetings, follow search results, measure advertisements, or process analytics traffic. Security products are accustomed to allowing those domains.<\/p>\n<h3>The final login page rebuilds itself for each victim<\/h3>\n<p>The attack carries the recipient&#8217;s email address through the chain, sometimes encoded in the part of the URL after a # symbol. When the final page loads, it extracts the company domain from that address and uses it to create a personalized login experience.<\/p><div id=\"mwtad4237467839\" class=\"gas_fallback-ad_309686-ad_309685-placement_406668\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The page can fetch the organization&#8217;s real logo, use a current screenshot of its public website as the background, prefill the employee&#8217;s email address, and localize the interface into one of 16 languages. The victim sees familiar branding that appears to confirm the email was intended for them.<\/p>\n<h3>The campaign steals credentials or installs remote access<\/h3>\n<p>One path presents a fake Microsoft or shared-document sign-in and sends the submitted password to the operators. Some versions deliberately reject the first password and collect a second entry before redirecting the victim to the real company website.<\/p>\n<p>Another path displays a false identity-verification request and installs ScreenConnect, a legitimate remote monitoring tool. When installed for the attacker, it can provide persistent access to the computer even after a password is changed.<\/p><div id=\"mwtad649975653\" class=\"gas_fallback-ad_381401-ad_309685-placement_406669\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<ul>\n<li>The campaign uses several business email themes rather than one fixed message.<\/li>\n<li>Observed lures include document reviews, mailbox expiry, package delivery, payment notices, government benefits, and voicemail alerts.<\/li>\n<li>Every observed path uses at least one legitimate Google service as an intermediary.<\/li>\n<li>The victim&#8217;s email can be carried in a URL fragment that many server logs do not record.<\/li>\n<li>The final page checks whether the email domain has real mail servers before showing the form.<\/li>\n<li>The victim&#8217;s real company logo and website screenshot are loaded dynamically.<\/li>\n<li>Credentials are sent to the operators through a Telegram bot.<\/li>\n<li>A second route installs ScreenConnect for persistent remote access.<\/li>\n<li>Google and the brands shown in the emails are being abused and are not running the scam.<\/li>\n<\/ul>\n<div id=\"mwtad1458002101\" class=\"gas_fallback-ad_309747-ad_309685-placement_406661\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Why Trusted Google Links Help the Email Pass Inspection<\/h2>\n<p>Email gateways and employees both look for suspicious domains. A message linking directly to an unknown phishing host is easier to block and easier for a person to question. The campaign avoids that obvious first impression by placing a real Google address at the front.<\/p>\n<p>Redirects are a normal part of the web. Search engines, advertising platforms, analytics tools, and meeting services routinely send visitors to external destinations. Blocking every redirect from a major provider would break legitimate business activity.<\/p>\n<div id=\"mwtad3599527647\" class=\"gas_fallback-ad_381404-ad_309685-placement_406670\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>The attackers chain these functions together so the link looks clean at multiple inspection points. A scanner may visit the first address, recognize Google, and stop before the final destination becomes active for the intended person.<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"675\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" alt=\"Trusted redirect chain used in the Google Redirect Phishing Uses Trusted Links to Steal Logins investigation\" class=\"wp-image-416538 lazyload\" title=\"\" sizes=\"auto, (max-width: 1200px) 100vw, 1200px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/google-redirect-phishing-trusted-links-2-final.png\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/google-redirect-phishing-trusted-links-2-final.png 1200w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/google-redirect-phishing-trusted-links-2-final-300x169.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/google-redirect-phishing-trusted-links-2-final-1024x576.png 1024w\"><\/figure>\n<p>The URL fragment adds another layer. Text after a # symbol is normally processed inside the browser and is not sent to every server along the route. The campaign uses that space to carry a preselected email address to the final page while hiding it from many intermediary logs.<\/p>\n<p>The phishing kit also filters visitors. It can check the IP address, browser, language, and the presence of valid mail records for the submitted company domain. Researchers or automated sandboxes using invented addresses may receive nothing useful.<\/p>\n<div id=\"mwtad1822260985\" class=\"mwtadp5 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"8560433799\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>By the time a genuine employee reaches the login page, it already shows the correct email, organization name, logo, and web background. The personalization is assembled from public information. It does not prove that the employer created the page.<\/p>\n<p>The wide range of lure themes also makes campaign-wide warnings harder. One employee may report a fake package email while another sees a document review or voicemail. The emails look unrelated even though the redirect and credential-harvesting machinery is shared.<\/p>\n<p>That is why the behavior after the click matters more than the subject line. An unexpected message that passes through trusted infrastructure and ends at an unfamiliar authentication page should be reported regardless of the brand used in the email.<\/p>\n<div id=\"mwtad1412415766\" class=\"gas_fallback-ad_309748-ad_309685-placement_406662\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What the Link, Personalization, Password Prompt, and Research Reveal<\/h2>\n<h3>The first domain is not the final destination<\/h3>\n<div id=\"mwtad424374433\" class=\"mwtadp6 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"4034304343\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>A URL can begin with google.com and still contain a parameter that tells the service where to send the browser next. Security decisions must account for the complete redirect chain, not only the first hostname.<\/p>\n<p>Do not approve a sign-in merely because you remember seeing Google earlier. When the form appears, inspect the current address and ask whether that exact domain is the normal login service for the organization.<\/p>\n<p>Browser history can make the chain difficult to reconstruct later because some redirects happen almost instantly. Saving the original email and copying the complete link gives a security team better evidence than a screenshot of only the final form.<\/p>\n<h3>The familiar company page is generated from public data<\/h3>\n<p>Company logos, favicons, and public website screenshots are easy to retrieve automatically. The phishing kit uses the domain after the @ in the victim&#8217;s email address to request those assets.<\/p>\n<p>A personalized page can therefore appear seconds after the click without the attacker having access to the company. The victim&#8217;s own email address supplied all the information needed to build it.<\/p>\n<h3>The first password always fails on purpose<\/h3>\n<p>Some variants show an invalid-password message after the first submission, regardless of whether the password was correct. The victim enters it again carefully, giving the attackers a second version and increasing their confidence that they captured the right credential.<\/p>\n<p>After the second entry, the page redirects to the real company website. That ordinary ending can make the failed sign-in seem like a temporary technical issue.<\/p>\n<h3>The campaign has been independently analyzed<\/h3>\n<p><a href=\"https:\/\/blog.knowbe4.com\/bypassing-the-gatekeepers-how-a-global-phishing-campaign-turns-googles-infrastructure-into-a-trust-proxy\" rel=\"noopener noreferrer\" target=\"_blank\">KnowBe4 Threat Lab published the redirect chains, phishing code, lure examples, and credential-exfiltration behavior<\/a>. Researchers also documented the ScreenConnect installation route and the real-time company branding used by the final page.<\/p>\n<p>The endpoint list can change as providers close abused paths and operators register new domains. The lasting warning is a trusted redirect that ends at an unexpected login or identity-verification page outside the normal account workflow.<\/p>\n<div id=\"mwtad2322118365\" class=\"gas_fallback-ad_318930-ad_309685-placement_406663\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3818335085\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the Google Redirect Phishing Scam Works<\/h2>\n<h3>Step 1: A business-themed email creates a reason to click<\/h3>\n<p>The message may imitate DocuSign, SafeSend ONE, Microsoft 365, FedEx, OneDrive, QuickBooks, Social Security, or a voicemail service. Each theme gives the recipient a familiar task with a deadline.<\/p>\n<p>The campaign targets organizations across manufacturing, government, finance, and nonprofit sectors. The subject and body can include the recipient&#8217;s name or company domain.<\/p>\n<p>Different themes let the same infrastructure reach people with different responsibilities. A finance employee may respond to a QuickBooks notice, while an administrator may be more likely to open a benefits or shared-document message.<\/p>\n<h3>Step 2: The embedded URL points to a real Google service<\/h3>\n<p>The visible link uses an allowed Google-owned domain. Behind it, query parameters specify another redirect endpoint or the eventual attacker-controlled destination.<\/p>\n<p>Some paths use several hops, such as Google Meet, Google Search, and DoubleClick. Others use Custom Search, Image Search, Tag Manager, or Analytics-related behavior.<\/p>\n<h3>Step 3: The victim&#8217;s email travels in the URL<\/h3>\n<p>The address may be encoded or placed after a # symbol. This allows the final page to know who clicked while keeping the targeting information out of many server-side request logs.<\/p>\n<p>An email address embedded after # in a link is not automatically malicious, but it is a strong sign that the destination is preparing a personalized session.<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"675\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" alt=\"Personalized company login page used in the Google Redirect Phishing Uses Trusted Links to Steal Logins investigation\" class=\"wp-image-416539 lazyload\" title=\"\" sizes=\"auto, (max-width: 1200px) 100vw, 1200px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/google-redirect-phishing-trusted-links-3-final.png\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/google-redirect-phishing-trusted-links-3-final.png 1200w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/google-redirect-phishing-trusted-links-3-final-300x169.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/google-redirect-phishing-trusted-links-3-final-1024x576.png 1024w\"><\/figure>\n<h3>Step 4: The final site filters automated visitors<\/h3>\n<p>The landing infrastructure can show a short waiting screen or fake human-verification prompt. In the background, it collects browser and location information and checks whether the target company has valid mail records.<\/p>\n<p>Scanners that do not click, wait, or use a real corporate domain can be filtered out. A genuine employee receives the full phishing page.<\/p>\n<h3>Step 5: A company-branded login form is assembled<\/h3>\n<p>The kit fetches the organization&#8217;s real logo and a screenshot of its public website. It fills in the recipient&#8217;s email, changes the tab title, and selects a language based on the browser.<\/p>\n<p>The page resembles a custom single sign-on portal even though it was generated by an attacker who knew only the email address.<\/p>\n<h3>Step 6: Credentials or remote access are captured<\/h3>\n<p>On the credential path, the password and session details are sent to a Telegram bot. A forced failure may collect the password twice before the victim is returned to a real site.<\/p>\n<p>On the remote-access path, a fake identity-verification step installs ScreenConnect. The operator can then interact with the computer, view data, and maintain access independently of the stolen password.<\/p>\n<div id=\"mwtad2840052906\" class=\"gas_fallback-ad_381388-ad_309685-placement_406705\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3191649120\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Warning Signs Along the Redirect Chain<\/h2>\n<ul>\n<li>The email creates an unexpected document, mailbox, delivery, payment, benefit, or voicemail task.<\/li>\n<li>The link contains a long Google URL followed by encoded parameters.<\/li>\n<li>An email address appears in the link, especially after a # symbol.<\/li>\n<li>The browser passes through several unrelated Google services before showing a login.<\/li>\n<li>The final form is not on the organization&#8217;s normal identity-provider domain.<\/li>\n<li>The page already knows the email address and displays the company logo.<\/li>\n<li>A first password is rejected immediately and the same form asks for it again.<\/li>\n<li>A document page requests device-code authorization rather than ordinary file access.<\/li>\n<li>An identity check asks you to download ScreenConnect or another remote-support tool.<\/li>\n<li>The page uses a fake CAPTCHA or waiting screen before deciding what content to show.<\/li>\n<\/ul>\n<p>Open the named service independently. If a document, voicemail, payment, or delivery is real, it should be visible after you sign in through a known bookmark or official application.<\/p>\n<div id=\"mwtad1321577524\" class=\"gas_fallback-ad_381392-ad_309685-placement_406664\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What to Do if You Have Fallen Victim to This Scam<\/h2>\n<ol>\n<li><strong>Use a clean device and change the affected password immediately.<\/strong> Begin with the corporate or primary email account.<\/li>\n<li><strong>Revoke active sessions and authentication tokens.<\/strong> A password reset may not close every session or device-code authorization.<\/li>\n<li><strong>Review multifactor methods and connected applications.<\/strong> Remove unknown devices, phone numbers, passkeys, app passwords, OAuth grants, and recovery addresses.<\/li>\n<li><strong>Notify the organization&#8217;s security team.<\/strong> Provide the original email, complete headers, full link, time of the click, and every page or prompt you saw.<\/li>\n<li><strong>Check mailbox rules and delegated access.<\/strong> Attackers often create forwarding rules or hidden permissions after gaining entry.<\/li>\n<li><strong>Disconnect the computer if ScreenConnect was installed.<\/strong> Treat the endpoint as actively compromised and do not use it for further account recovery.<\/li>\n<li><strong>Remove unauthorized remote-access software through incident response.<\/strong> In a business environment, isolation, forensic collection, and a system rebuild may be necessary.<\/li>\n<li><strong>Inspect recent cloud activity.<\/strong> Look for unusual downloads, sent messages, new inbox rules, file shares, login locations, and application consent.<\/li>\n<li><strong>Warn contacts who received messages from the compromised account.<\/strong> Attackers may reuse a real mailbox to continue the campaign internally.<\/li>\n<\/ol>\n<div id=\"mwtad2337277847\" class=\"gas_fallback-ad_381392-ad_309685-placement_406665\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Frequently Asked Questions<\/h2>\n<h3>Is Google running the phishing campaign?<\/h3>\n<p>No. Attackers abuse legitimate redirect and tracking functions on Google infrastructure before sending victims to their own pages.<\/p>\n<h3>Can a real google.com link lead to a scam?<\/h3>\n<p>Yes. A Google URL can contain a parameter that redirects the browser elsewhere. Check the final domain where a login or download is requested.<\/p>\n<h3>Why does the page show my real company logo?<\/h3>\n<p>The phishing kit derives the company domain from your email address and fetches public logo and website images automatically.<\/p>\n<h3>Why did my first password fail?<\/h3>\n<p>Some versions reject the first entry deliberately so the victim submits a second password. Both attempts can be sent to the attacker.<\/p>\n<h3>What is the risk of installing ScreenConnect?<\/h3>\n<p>ScreenConnect is a legitimate support product, but an attacker-controlled installation can provide persistent remote access to files, applications, and logged-in accounts.<\/p>\n<h3>Does multifactor authentication stop this attack?<\/h3>\n<p>It helps, but the campaign can abuse device-code flows, steal active sessions, or install remote-access software. Report the incident even if MFA was enabled.<\/p>\n<h2>The Bottom Line<\/h2>\n<p>This phishing campaign uses real Google domains as stepping stones, not as the final destination. That distinction lets a malicious link inherit trust from infrastructure that users and security systems encounter every day.<\/p>\n<p>The company logo, website background, prefilled email, and correct language are generated from public data. They make the page personal, but they do not make it authentic.<\/p>\n<p>If you entered credentials or installed remote-access software, respond as though the account and computer are compromised. Revoke sessions, notify security, isolate the device, and investigate what the attacker could access.<\/p>\n<div id=\"mwtad2509302259\" class=\"gas_fallback-ad_176819-ad_309685-placement_406666\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8386082122\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>An email says a document needs approval, a mailbox will expire, a package was missed, or a payment is waiting. The embedded link begins on a genuine Google domain, so the usual advice to inspect &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"Google Redirect Phishing Uses Trusted Links to Steal Logins\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/google-redirect-phishing-trusted-links\/#more-416536\" aria-label=\"Read more about Google Redirect Phishing Uses Trusted Links to Steal Logins\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":416537,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[],"class_list":["post-416536","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/416536","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=416536"}],"version-history":[{"count":7,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/416536\/revisions"}],"predecessor-version":[{"id":416570,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/416536\/revisions\/416570"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/416537"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=416536"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=416536"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=416536"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}