Phishing Scam Hides Behind Trusted Google Links to Steal Credentials
A new phishing campaign is exploiting the trust users place in Google by routing malicious links through multiple Google services before redirecting victims to fake login pages. Because the initial link appears to come from a legitimate Google domain, it can slip past email security filters and look convincing to recipients.
Once victims click through the chain of redirects, they are either prompted to enter their login credentials on a fake page or tricked into installing ScreenConnect, a legitimate remote access tool that attackers can misuse to take control of a device. This tactic allows criminals to bypass basic security checks that rely on scanning the first link in an email rather than following it through to its final destination.
This technique highlights how attackers are increasingly using trusted platforms as a stepping stone to make phishing attempts harder to spot. Small businesses without advanced email filtering are particularly at risk, as staff may not think twice about clicking a link that appears to originate from Google.