Threat IntelligenceSep 8, 2026
Attackers Use Multi-Hop Google Redirects for Phishing Campaign
Attackers use multi-hop Google redirects for phishing, harvesting credentials or installing ScreenConnect.
Summary
Threat actors are employing a sophisticated phishing campaign that leverages multiple Google services to create a chain of redirects, making it harder for security teams to detect and block. This multi-hop approach ultimately leads victims to pages designed to steal credentials or deploy ScreenConnect for remote access.
Indicators of Compromise
- malware — ScreenConnect
Entities
Google (vendor)ScreenConnect (product)