A familiar Google address in a suspicious email may be exactly what attackers want you to trust.
KnowBe4 Threat Lab uncovered an active, wide-scale phishing campaign that routes corporate targets through legitimate Google services before redirecting them to malicious pages. Researchers found the setup can help links survive early security checks.
The attack becomes increasingly personalized as the redirect chain progresses, with some victims receiving phishing pages tailored to their employer and email address.
Redirect tricks keep the phishing page out of sight
Campaign variants moved through services such as Google Meet, Search, and DoubleClick in different combinations, complicating attempts to block one fixed path.
Some links also carried targeting details in a part of the URL that earlier services did not receive, keeping useful information away from some automated checks.
Before showing the final phishing page, the attacker-controlled site checks whether the visitor appears to be a real corporate target. Fake human-verification prompts and company-domain checks can reduce the chance that researchers or automated scanners see the malicious page.
Victims arrive at pages built around their own workplace
Visitors who clear those checks can land on a page assembled around their employer. The kit can reportedly pull the company’s real logo and place the login prompt over an image of its public website. Victim email addresses can also arrive pre-filled.
Support for 16 languages points to global targeting. KnowBe4 observed corporate targets across manufacturing and government, as well as finance and nonprofit organizations. Lures included document reviews and mailbox-expiration warnings, among other business messages.
Some sessions lead to fake Microsoft sign-in pages built to capture credentials or device authorization codes. Others use a false identity-verification prompt to install ScreenConnect, a legitimate remote administration tool attackers have abused in other compromises.
ScreenConnect raises the potential damage by giving an attacker interactive access to the endpoint instead of stopping at account theft.
The ScreenConnect path raises the stakes because it can give an attacker interactive access to the endpoint rather than limiting the compromise to stolen account credentials.
Trusted links demand different checks from employees and defenders
Employees should treat familiarity as a reason to verify, not as proof that a request is safe. A legitimate service at the start of a link or a polished login page at the end can still be part of a phishing attack.
| Who should act | What to watch for | What to do |
|---|---|---|
| Employees receiving a suspicious message | Unexpected document, voicemail, or account notices that send you through several pages before asking you to sign in | Open the service directly in its app or website instead of continuing through the message. Report suspicious requests to IT or security. |
| Anyone who entered credentials | Unexpected sign-in prompts or account activity after clicking a link | Change the password from a known-good device and alert the security team so recent sign-ins and active sessions can be reviewed. |
| Anyone who installed ScreenConnect | An identity-verification request that installed software or opened remote access | Contact IT or security immediately and have the endpoint checked for unauthorized access. |
| Security and IT teams | Trusted redirects ending at unfamiliar domains, suspicious authentication activity, or unapproved remote access tools | Review affected accounts and sessions, inspect endpoints, check for unauthorized ScreenConnect deployments, and hunt using the published campaign indicators. |
Security teams should not stop at a password reset if remote-access software may have been installed. MFA and credential resets can help protect the account, but they do not remove an attacker who already has control of the endpoint through an active remote-access session.
In those cases, the device itself should be treated as potentially compromised and investigated accordingly.
More cybersecurity news: Fake Minecraft sites kept WeedHack in circulation after defenders disrupted the malware operation’s original backend.





