Phishing Uses Google Links to Steal Microsoft Logins

eSecurity Planet · High sophistication
Last updated September 10, 2026

Researchers reported an active, large-scale phishing campaign that starts with links hosted on legitimate Google services, then redirects victims to attacker-controlled sites. The final pages mimic Microsoft sign-in or “identity verification” flows to steal credentials/MFA codes or trick targets into installing ScreenConnect remote-access software. The phishing pages can be personalized with the victim’s employer branding and pre-filled email address to look more convincing.

How the attack worked

Researchers at KnowBe4 Threat Lab identified an active, wide-scale phishing campaign that begins with links hosted on legitimate Google services. Victims click a link inside a message such as a document review or mailbox-expiration notice, and the link starts on a trusted Google service like Meet, Search, or DoubleClick before redirecting through a chain of pages. The final destination is an attacker-controlled site that mimics a Microsoft sign-in or identity verification flow. Depending on the variant, the end goal is either stealing Microsoft credentials and device authorization codes, or convincing the victim to install ScreenConnect, a legitimate remote administration tool, giving the attacker interactive access to the endpoint.

Why it succeeded

The use of legitimate Google services as the entry point is central to why this campaign works. A familiar Google address in a message may be exactly what makes a target trust the link enough to click. From there, redirect chains vary across campaign instances, which complicates efforts to block a single fixed path and helps the links survive early security checks. The attacker site also performs target filtering, using fake human-verification prompts and company-domain checks, to reduce the chance that automated scanners or researchers ever see the actual phishing page. Personalization adds another layer of credibility: some pages are tailored with the victim's employer logo and a pre-filled email address.

What to watch for

  • Messages that send you through several pages or redirects before asking for a sign-in
  • A final destination on an unfamiliar domain, even though the link started on a trusted Google service
  • A sign-in page that is unusually personalized, such as showing a company logo or pre-filling your email
  • An identity verification flow that asks you to install software, especially a remote access tool
  • Verification steps that do not match your organization's normal login process

Building resistance

Organizations across manufacturing, government, finance, and nonprofit sectors have been targeted, and the campaign supports multiple languages, indicating broad, opportunistic targeting rather than a narrow focus. Employees, IT helpdesk staff, and security teams should be trained to navigate directly to a service instead of clicking through a message, even when the initial link looks legitimate. Any request to install software during a supposed identity verification step should be treated as a serious warning sign and reported immediately. If ScreenConnect or another remote access tool may have been installed, a password or MFA reset alone is not sufficient. The device itself should be treated as potentially compromised and investigated accordingly, since this campaign extends beyond simple credential theft toward direct endpoint access.

Key findings

  • Active, wide-scale phishing campaign routes targets through legitimate Google services (e.g., Meet, Search, DoubleClick) before redirecting to malicious pages.
  • Redirect chains vary, making it harder to block a single fixed URL path and helping links “survive early security checks.”
  • Phishing becomes more personalized over the redirect chain; some pages are tailored to the victim’s employer and email address (including company logo and pre-filled email).
  • Attacker site performs target filtering (fake human-verification prompts and company-domain checks) to avoid showing the phishing page to scanners or researchers.
  • End goals include stealing Microsoft credentials/device authorization codes, or tricking users into installing ScreenConnect to gain interactive endpoint access.
  • Campaign observed across multiple industries (manufacturing, government, finance, nonprofit) and supports 16 languages (global targeting).

Who’s being targeted

  • Commonly targeted roles: All employees, Finance, HR, Executive assistants, IT helpdesk, Security team.
  • Affected industries: Manufacturing, Government, Finance, Nonprofit.
  • Attack channels: email, website.
  • Impersonated: Microsoft sign-in (with employer branding), Identity verification / security check flow.

Red flags to watch for

  • Message sends you through several pages/redirects before the sign-in prompt
  • Final destination is an unfamiliar domain even though the link starts on a trusted Google service
  • Login page is unusually personalized (company logo/website image) and may pre-fill your email unexpectedly
  • A sign-in/verification flow asks you to install software
  • Unexpected remote access tool installation request
  • Polished verification steps that don’t match your normal company login process
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How does this phishing campaign use Google links?

It routes targets through legitimate Google services such as Meet, Search, and DoubleClick before redirecting them to attacker-controlled pages, which helps the links survive early security checks.

What is the end goal of the attack?

The campaign either steals Microsoft credentials and device authorization codes through a fake sign-in page, or tricks victims into installing ScreenConnect, a legitimate remote administration tool, to gain interactive access to the device.

How does the phishing page avoid detection by security researchers?

The attacker-controlled site performs target filtering using fake human-verification prompts and company-domain checks so scanners or researchers are less likely to see the malicious page.

What should security teams do if ScreenConnect was installed?

Security teams should not stop at a password reset. If remote-access software may have been installed, the device itself should be treated as potentially compromised and investigated accordingly.

Read the video transcript

You get an email: "Action required, please review the attached document" with a legit-looking Google link. Feels safe, right? But this campaign chains through Google Meet, Search, or DoubleClick, then quietly lands you on a fake Microsoft sign-in page dressed up with your company logo and your email already filled in. That’s the trap: multiple redirects to dodge filters, then either steal your Microsoft password and MFA code, or push a fake identity check that installs ScreenConnect for full remote access. If a link starts on Google but sends you through weird redirects to a Microsoft login or identity check, stop. Close it, then go to office.com or your usual app directly and sign in from there.

Similar attacks

BlueMoon Phishing Lures Drop Chrome Zero-Day Chain

BlueMoon Phishing Lures Drop Chrome Zero-Day Chain

Researchers found multiple espionage groups using the same Chrome+Windows exploit kit (“BlueMoon”) within days of each other. The groups sent realistic phishing emails (internship requests, conference outreach, procurement inquiries, and vaccination appointments) that pushed victims to click links…

September 10, 2026
Hidden ChatGPT Tasks Leak Data Across Accounts

Hidden ChatGPT Tasks Leak Data Across Accounts

Check Point researchers demonstrated a real proof-of-concept where a victim’s ChatGPT session could be tricked into running hidden, attacker-controlled tasks in parallel with the user’s normal request. In the demo, the attacker used a covert cross-account channel to make ChatGPT access the victim’s…

September 8, 2026
Gambling Goblin Hijacks Gov Sites for Phishing

Gambling Goblin Hijacks Gov Sites for Phishing

Researchers say a Chinese-speaking cybercrime group compromised Brazilian government and education websites and used them as “trusted” entry points to quietly redirect visitors to attacker-run phishing pages. The fake pages impersonated well-known app stores (Google Play, Microsoft Store, Amazon)…

September 2, 2026
DocuSign Share Lure Steals Microsoft 365 Sessions

DocuSign Share Lure Steals Microsoft 365 Sessions

Researchers described an active phishing operation using real DocuSign notifications to trick employees into opening a fake “remittance-advice” document and clicking a hidden malicious link. The attack routes victims through legitimate Microsoft/Google pages before landing on an…

August 28, 2026
NovaCookies Uses Real DocuSign to Steal M365 Sessions

NovaCookies Uses Real DocuSign to Steal M365 Sessions

Researchers report NovaCookies, a phishing-as-a-service toolkit that steals Microsoft 365 session cookies by proxying real logins in real time. The campaigns abuse genuine DocuSign email notifications to deliver a malicious document link that ultimately leads to an attacker-controlled Microsoft 365…

August 26, 2026
Phish Login, Then Add Your Own Google Passkey

Phish Login, Then Add Your Own Google Passkey

Researchers describe a phishing workflow where an attacker logs into a victim’s Google account using stolen password + authenticator code, then quickly enrolls a new passkey to keep access even if the password is changed. The trick relies on victims choosing a weaker sign-in fallback (one-time…

August 26, 2026