Attackers Use Multi-Hop Google Redirects for Phishing Campaign

Published September 8, 2026

Attackers are sending fake Google login pages via a chain of Google services to trick users into entering their passwords. This lets them steal accounts or install remote access software on victims' devices.

Report priority
Medium
Targets
Google

How it works

  • Attackers send users a link that looks like a real Google login page.
  • When clicked, it first redirects to a legitimate Google service, then to a fake Google login page hosted on another Google service.
  • This tricks users into entering their passwords on the fake page, which sends the credentials to the attackers.
  • The attackers then use those credentials to access the victim's Google account or install ScreenConnect remote access software on their device.

What to do

If you clicked a suspicious link claiming to be a Google login page and entered your credentials, check your Google account for any unusual activity, such as unknown logins or installed apps. If you suspect you've been targeted, review your account settings and enable two-factor authentication immediately.

If you entered your credentials on a fake login page, change your Google password right away. Enable two-factor authentication in your Google Account settings for extra security. Monitor your account for any unauthorized access or changes. If you see ScreenConnect or any unknown remote access software, remove it immediately.

Technical details

A victim receives an email with a link that looks like a Google login page. When clicked, the link first goes to a Google Drive file, then to a Google Sites page, and finally to a fake Google login page hosted on Google Forms. The victim enters their credentials on the fake page, which are then sent to the attackers.

Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access.