Back to Intelligence

Google Infrastructure Trust-Proxy Phishing Campaign + ScreenConnect Delivery: OTX Pulse Analysis — Enterprise Detection Pack

SA
Security Arsenal Team
October 11, 2026
11 min read

Threat Summary

A new AlienVault OTX pulse documents a global phishing operation that treats Google's own infrastructure as a laundering layer for malicious traffic. Rather than standing up obviously hostile infrastructure, the adversary chains together six distinct Google properties — Google Meet, Google Search, DoubleClick, Google Custom Search, Google Tag Manager, and Google Analytics — to proxy victims through domains that every email security gateway, DNS filter, and enterprise firewall already trusts.

The attack chain works as follows:

  1. Lure delivery — A phishing email containing a Google Meet or Google Search URL passes secure email gateway (SEG) inspection because the domain reputation is pristine.
  2. Trust-proxy redirect chain — The victim is bounced through open redirects and tracking parameters across DoubleClick, Custom Search, Tag Manager, and Analytics endpoints. Each hop inherits Google's trust, defeating URL rewriting, sandbox detonation, and reputation scoring.
  3. Victim fingerprinting — The victim's email address is encoded directly into the URL fragment (# component), which is never sent to the server but is read client-side by the phishing kit's JavaScript. This enables pre-filled credential forms — a hallmark of targeted credential harvesting.
  4. Payload / credential capture — The final landing infrastructure (the IOC domains below) hosts credential-harvesting pages and, in observed cases, distribution of ScreenConnect — a legitimate remote access tool abused as a persistent remote-access trojan (RAT).

Objective: Credential theft at scale against enterprise identities, with ScreenConnect providing durable post-compromise access for follow-on activity (lateral movement, data theft, or resale of access on dark web markets). Targeted verticals include Manufacturing, Government, Finance, and NGOs — sectors whose credentials command premium prices in initial-access-broker (IAB) markets.

The strategic concern for defenders: this technique neutralizes the entire class of controls built on domain reputation. Detection must shift to behavioral signals — redirect chain analysis, URL fragment patterns, ScreenConnect installation telemetry, and egress to the low-reputation landing domains that sit at the end of the chain.

Threat Actor / Malware Profile

Attribution: Unknown (per OTX). The tradecraft — legitimate-infrastructure abuse, multi-hop redirect laundering, and commodity RAT delivery — is consistent with financially motivated phishing-as-a-service (PhaaS) operators who sell harvested credentials and RAT access onward.

ScreenConnect (ConnectWise Control) — abused as RAT:

  • Distribution method: Delivered via phishing landing pages, typically as a trojanized installer, a fake "meeting client," or an MSI pushed after credential capture. Attackers register free/trial ScreenConnect instances and generate victim-specific installer URLs.
  • Payload behavior: Once installed, the ScreenConnect client (ScreenConnect.ClientService.exe) provides full interactive remote control, file transfer, command execution, and screen capture — all over legitimate, digitally signed binaries that evade most application-control and AV policies.
  • C2 communication: Outbound TLS to attacker-controlled ScreenConnect relay instances (frequently on non-standard ports such as 8040/8041) or to attacker-registered cloud relay domains. Because traffic is encrypted and signed, C2 blends with legitimate remote-support traffic.
  • Persistence mechanism: Installs as a Windows service (e.g., ScreenConnect Client (<instance-id>)) set to auto-start; survives reboots and requires no exploitation. Registry artifacts under HKLM\SYSTEM\CurrentControlSet\Services\ScreenConnect Client* and HKLM\SOFTWARE\ScreenConnect Client are reliable forensic markers.
  • Anti-analysis techniques: The phishing kit gates the payload behind the URL-fragment email check (fragments are invisible to server-side sandboxes), fingerprinting logic that serves benign content to scanners, and the Google redirect chain that defeats automated detonation of the original URL.

IOC Analysis

The pulse contains 23 indicators, dominated by domain and hostname indicators — the landing infrastructure behind the Google trust-proxy chain:

TypeExamplesRole
Domainfurqanmustafa.com, pittni.com, vazquezfleytas.com, edificiocristal.pt, velvorra.comPhishing landing / redirect termination domains
Hostnameodahlzr5lm.reliabilityinoperations.de, cloudbemismanufacturingcompanygroup.rydezyhrsysteminc.vu, servicetriumphgroupsimplyappraisals.spectrhwqumbrands.vuVictim-specific or organization-mimicking subdomains used to personalize lures (note the manufacturing-themed subdomain naming consistent with the targeted sectors)

Operationalization guidance for SOC teams:

  • DNS/proxy blocking: Push all domains and full hostnames into DNS sinkhole (RPZ) and web proxy block lists. Subdomain-heavy indicators (.vu TLD hostnames) should be blocked at both the FQDN and parent-domain level, as these operators rotate subdomains rapidly.
  • Retroactive hunting: Query 30–90 days of DNS resolver and proxy logs for resolutions of these indicators — any hit indicates a victim who completed the redirect chain and likely surrendered credentials or received a payload.
  • Redirect-chain telemetry: Alert on HTTP sessions where a referrer sequence includes google.com/doubleclick.net/googletagmanager.com terminating at any low-reputation or newly registered domain. This catches the campaign even when landing domains rotate.
  • Fragment-based detection limitation: URL fragments (#email=victim@corp.com) are not transmitted to servers and will not appear in proxy logs — but email gateways can still inspect full URLs in message bodies. Create SEG rules flagging inbound URLs containing base64-encoded or plaintext corporate email addresses in fragments or query strings.
  • Tooling: Enrich indicators in your TIP (e.g., via OTX DirectConnect/API pull), then correlate with EDR network telemetry. WHOIS/PassiveDNS pivoting on the parent domains will surface sibling infrastructure.

Detection Engineering

YAML
---
title: Suspicious Redirect Chain via Google Infrastructure to Untrusted Domain
id: 7c3a1f2e-9b41-4d8a-a2c6-1e5f8a0b3d21
status: experimental
description: Detects web proxy sessions where a Google-owned property (Search, DoubleClick, Tag Manager, Analytics, Custom Search, Meet) is the referrer immediately before navigation to a known-bad or untrusted external domain. Characteristic of the trust-proxy phishing campaign abusing Google open redirects.
author: Security Arsenal Threat Intelligence
date: 2026/10/11
references:
    - https://blog.knowbe4.com/bypassing-the-gatekeepers-how-a-global-phishing-campaign-turns-googles-infrastructure-into-a-trust-proxy
logsource:
    category: proxy
product: webserver
detection:
    selection_referrer:
        c-referrer|contains:
            - 'google.com/url'
            - 'doubleclick.net'
            - 'googletagmanager.com'
            - 'google-analytics.com'
            - 'cse.google.com'
            - 'meet.google.com'
    selection_dest:
        c-uri|contains:
            - 'furqanmustafa.com'
            - 'pittni.com'
            - 'vazquezfleytas.com'
            - 'edificiocristal.pt'
            - 'velvorra.com'
            - 'reliabilityinoperations.de'
            - 'rydezyhrsysteminc.vu'
            - 'spectrhwqumbrands.vu'
    condition: selection_referrer and selection_dest
falsepositives:
    - Legitimate Google ad click-throughs to advertiser domains (tune with domain age/reputation filtering)
level: high
tags:
    - attack.initial_access
    - attack.t1566.002
---
title: ScreenConnect Remote Access Client Installation or Execution
id: 2d8b4c1a-6e57-4f92-b3d9-8a1c7e0f5b42
status: experimental
description: Detects installation service creation or execution of the ScreenConnect (ConnectWise Control) client, a legitimate RMM tool abused by phishing operators for persistent remote access following credential harvesting.
author: Security Arsenal Threat Intelligence
date: 2026/10/11
references:
    - https://blog.knowbe4.com/bypassing-the-gatekeepers-how-a-global-phishing-campaign-turns-googles-infrastructure-into-a-trust-proxy
logsource:
    category: process_creation
    product: windows
detection:
    selection_img:
        Image|endswith:
            - '\ScreenConnect.ClientService.exe'
            - '\ScreenConnect.WindowsClient.exe'
            - '\ScreenConnect.Client.exe'
    selection_service:
        CommandLine|contains:
            - 'ScreenConnect Client'
            - 'screenconnect'
    filter_approved_rmm:
        Image|startswith:
            - 'C:\Program Files\ScreenConnect'
        # Add your approved RMM deployment paths here if ScreenConnect is sanctioned
    condition: (selection_img or selection_service) and not filter_approved_rmm
falsepositives:
    - Environments where ScreenConnect is the sanctioned RMM platform (suppress via approved path/publisher)
level: high
tags:
    - attack.command_and_control
    - attack.t1219
    - attack.persistence
    - attack.t1543.003
---
title: Phishing URL with Encoded Victim Email in Fragment or Query String
id: 9f1e6d3b-4c28-4a75-9e14-3b7d2f8c6a90
status: experimental
description: Detects inbound email URLs or web requests containing an email address encoded in the URL fragment or query string - a fingerprinting technique used by the credential-harvesting kit to pre-fill victim identity on phishing pages.
author: Security Arsenal Threat Intelligence
date: 2026/10/11
references:
    - https://blog.knowbe4.com/bypassing-the-gatekeepers-how-a-global-phishing-campaign-turns-googles-infrastructure-into-a-trust-proxy
logsource:
    category: proxy
product: webserver
detection:
    selection_email_param:
        c-uri|re: '(?i)(#|\?|&)(email|e|user|u|login|id)=([a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}|[A-Za-z0-9+/=]{16,})'
    selection_external:
        c-uri|contains:
            - '.vu/'
            - '.de/'
            - '.com/'
            - '.pt/'
    filter_google:
        c-uri|contains:
            - 'google.com'
            - 'googleapis.com'
    condition: selection_email_param and selection_external and not filter_google
falsepositives:
    - Marketing platforms using email tokens in tracking links (tune by sender reputation)
level: medium
tags:
    - attack.initial_access
    - attack.t1566
    - attack.collection
KQL — Microsoft Sentinel / Defender
// Hunt: Google trust-proxy phishing chain + ScreenConnect C2 (Microsoft Sentinel)
// Lookback: 30 days - adjust to your retention and first-seen IOC dates
let Lookback = 30d;
let PhishIOCs = dynamic([
    "furqanmustafa.com","pittni.com","vazquezfleytas.com","edificiocristal.pt",
    "velvorra.com","reliabilityinoperations.de","rydezyhrsysteminc.vu","spectrhwqumbrands.vu"
]);
// 1) Egress to known phishing landing / C2 domains
let LandingHits = DeviceNetworkEvents
| where TimeGenerated > ago(Lookback)
| where RemoteUrl has_any (PhishIOCs) or RemoteUrl endswith ".vu"
| project LandingHitTime=TimeGenerated, DeviceName, InitiatingProcessFileName,
          InitiatingProcessCommandLine, RemoteUrl, RemoteIP, ActionType;
// 2) ScreenConnect client execution or installation on any endpoint
let ScreenConnectActivity = DeviceProcessEvents
| where TimeGenerated > ago(Lookback)
| where FileName has_any ("ScreenConnect.ClientService.exe","ScreenConnect.WindowsClient.exe","ScreenConnect.Client.exe")
   or ProcessCommandLine has "screenconnect"
| project SCEngTime=TimeGenerated, DeviceName, FileName, ProcessCommandLine, InitiatingProcessFileName, SHA256;
// 3) Correlate: endpoints that hit landing infrastructure AND ran ScreenConnect (probable full compromise)
LandingHits
| join kind=inner ScreenConnectActivity on DeviceName
| extend TimeDelta = abs(datetime_diff('minute', SCEngTime, LandingHitTime))
| project DeviceName, LandingHitTime, RemoteUrl, RemoteIP, InitiatingProcessFileName,
          SCEngTime, FileName, ProcessCommandLine, TimeDelta, SHA256
| order by DeviceName asc, LandingHitTime asc;
// Secondary hunt: URL fragments/query strings carrying corporate email addresses in mail flow
// EmailUrlInfo (if MDE for Office licensed)
EmailUrlInfo
| where TimeGenerated > ago(Lookback)
| where Url matches regex @"(?i)(#|\?|&)(email|e|user|u|login)=([a-zA-Z0-9._%+-]+@|[A-Za-z0-9+/=]{16,})"
| project TimeGenerated, Url, UrlDomain, NetworkMessageId
| order by TimeGenerated desc;
PowerShell
# ============================================================
# IOC Hunt: Google Trust-Proxy Phishing Campaign + ScreenConnect
# Security Arsenal - Threat Intelligence | 2026-10-11
# Run elevated on suspected endpoints or via your EDR live-response
# ============================================================

$PhishDomains = @(
    "furqanmustafa.com","pittni.com","vazquezfleytas.com",
    "edificiocristal.pt","velvorra.com",
    "reliabilityinoperations.de","rydezyhrsysteminc.vu","spectrhwqumbrands.vu"
)

Write-Host "`n[1] ScreenConnect service / persistence artifacts" -ForegroundColor Cyan
Get-Service | Where-Object { $_.Name -like "*ScreenConnect*" -or $_.DisplayName -like "*ScreenConnect*" } |
    Select-Object Name, DisplayName, Status, StartType | Format-Table -AutoSize

Write-Host "`n[2] ScreenConnect registry persistence keys" -ForegroundColor Cyan
$RegPaths = @(
    "HKLM:\SYSTEM\CurrentControlSet\Services",
    "HKLM:\SOFTWARE",
    "HKCU:\SOFTWARE"
)
foreach ($base in $RegPaths) {
    Get-ChildItem $base -ErrorAction SilentlyContinue |
        Where-Object { $_.PSChildName -like "*ScreenConnect*" } |
        ForEach-Object { Write-Host "  HIT: $($_.PSPath)" -ForegroundColor Red }
}

Write-Host "`n[3] ScreenConnect binaries on disk (outside sanctioned paths)" -ForegroundColor Cyan
$scFiles = @(
    "$env:ProgramFiles","${env:ProgramFiles(x86)}","$env:ProgramData","$env:TEMP","$env:LOCALAPPDATA"
) | ForEach-Object {
    Get-ChildItem $_ -Recurse -Filter "ScreenConnect*.exe" -ErrorAction SilentlyContinue
}
$scFiles | Select-Object FullName, CreationTime, Length | Format-Table -AutoSize

Write-Host "`n[4] Active connections to ScreenConnect ports (8040/8041) or phishing C2" -ForegroundColor Cyan
Get-NetTCPConnection -State Established -ErrorAction SilentlyContinue |
    Where-Object { $_.RemotePort -in 8040,8041 } |
    Select-Object LocalAddress, LocalPort, RemoteAddress, RemotePort, OwningProcess,
        @{N='Process';E={(Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue).ProcessName}} |
    Format-Table -AutoSize

Write-Host "`n[5] DNS cache check for phishing landing domains" -ForegroundColor Cyan
$dnsCache = Get-DnsClientCache -ErrorAction SilentlyContinue
foreach ($d in $PhishDomains) {
    $hits = $dnsCache | Where-Object { $_.Entry -like "*$d*" }
    if ($hits) {
        $hits | ForEach-Object { Write-Host "  HIT: $($_.Entry) -> $($_.Data)" -ForegroundColor Red }
    }
}

Write-Host "`n[6] Recent browser history artifacts (Chrome/Edge) for landing domains" -ForegroundColor Cyan
$historyPaths = @(
    "$env:LOCALAPPDATA\Google\Chrome\User Data\Default\History",
    "$env:LOCALAPPDATA\Microsoft\Edge\User Data\Default\History"
)
foreach ($hp in $historyPaths) {
    if (Test-Path $hp) {
        $tmp = Join-Path $env:TEMP ("hist_" + [guid]::NewGuid().ToString("N") + ".db")
        Copy-Item $hp $tmp -Force -ErrorAction SilentlyContinue
        # Requires sqlite3.exe in PATH; otherwise export $tmp for offline analysis
        foreach ($d in $PhishDomains) {
            $r = & sqlite3 $tmp "SELECT url, datetime(last_visit_time/1000000-11644473600,'unixepoch') FROM urls WHERE url LIKE '%$d%';" 2>$null
            if ($r) { $r | ForEach-Object { Write-Host "  HIT [$hp]: $_" -ForegroundColor Red } }
        }
        Remove-Item $tmp -Force -ErrorAction SilentlyContinue
    }
}

Write-Host "`n[*] Hunt complete. Any HIT = escalate to IR; treat host + associated identity as compromised.`n" -ForegroundColor Green

Response Priorities

Immediate (0–4 hours):

  • Block all 23 IOC domains/hostnames at DNS (RPZ), web proxy, and EDR custom indicators; block the .vu-based FQDNs at parent-domain level to preempt subdomain rotation.
  • Run the KQL correlation query and PowerShell hunt across the fleet; any endpoint with both a landing-domain hit and ScreenConnect execution is a confirmed compromise — isolate immediately.
  • Inventory whether ScreenConnect is sanctioned in your environment. If not, alert on any execution; if yes, validate installed instances against approved relay URLs.
  • Add SEG rules flagging inbound URLs with corporate email addresses encoded in fragments or query parameters, and URLs chaining multiple Google redirect endpoints.

24 hours:

  • For every user whose browser resolved a landing domain or who appears in the EmailUrlInfo hunt: force credential reset, revoke all sessions and refresh tokens, and re-register MFA — assume credentials were captured the moment the phishing page rendered.
  • Audit Azure AD/Entra ID and IdP sign-in logs for those identities for anomalous logins (impossible travel, new MFA registrations, OAuth consent grants, mailbox forwarding rules) in the 72 hours surrounding the click.
  • If ScreenConnect ran on any host, treat the session as interactive access: review file transfer, command execution, and lateral-movement telemetry for the full dwell window, not just the endpoint.

1 week (architecture hardening):

  • Deploy application control (WDAC/AppLocker) to restrict RMM tooling to an approved allowlist — ScreenConnect, AnyDesk, TeamViewer, and similar binaries should not execute outside sanctioned paths and publishers.
  • Implement redirect-chain-aware web filtering: alert when Google-owned referrers chain to newly registered (<90 days) or low-reputation domains.
  • Move high-value verticals (finance, manufacturing OT-adjacent users, government) to phishing-resistant MFA (FIDO2/passkeys) — this campaign's entire monetization model collapses if harvested passwords cannot be replayed.
  • Feed the redirect-chain and fragment-detection logic into your detection backlog as durable analytics, since the landing domains will rotate but the tradecraft will persist.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.