Back to Intelligence

Google Trust-Proxy Phishing Chain + ScreenConnect Follow-On: OTX Detection Pack for Credential Harvesting

SA
Security Arsenal Team
October 11, 2026
8 min read

Excerpt

OTX: global phishing abuses six Google services as trusted redirects to harvest credentials across manufacturing, government, finance and NGOs; ScreenConnect flagged as possible follow-on.

Threat Summary

The pulse describes a global phishing operation that turns Google infrastructure into a trust proxy rather than relying only on look-alike domains. The reported chain strings together Google Meet, Search, DoubleClick, Custom Search, Tag Manager and Analytics so that secure email gateways, URL filters and users see trusted google.com-family infrastructure before the final redirect to attacker-controlled credential-harvesting pages. The lure appears tailored enough to encode the victim email address in URL fragments, which suggests pre-populated phishing forms, per-victim tracking and possible validation of inboxes before credential submission.

The actor is unattributed in the pulse, but the tradecraft is consistent with financially motivated initial-access and business-email-compromise operators rather than a single named APT. Targeted sectors listed are manufacturing, government, finance and NGOs. The campaign objective is credential harvesting at scale; the ScreenConnect tag should be treated as a high-value follow-on risk because abused RMM tooling can convert a stolen session or successful phish into durable hands-on access, rapid lateral movement and data staging.

Collectively, the pulse reveals three defensive truths: trusted cloud SaaS can be used as redirect armor, fragment-encoded recipient data can evade naive URL inspection because fragments are not always sent to servers, and RMM abuse after credential theft must be hunted even when the phishing payload is only a web page.

Threat Actor / Malware Profile

Adversary: unknown. Confidence is moderate for a coordinated campaign because the pulse reports repeated use of the same multi-property Google redirect pattern across sector-specific lures.

ScreenConnect / ConnectWise ScreenConnect profile: legitimate remote monitoring and management software frequently abused for unauthorized access. Distribution methods observed in the wild include malicious installer links after phishing, fake browser or meeting-update pages, trojanized support tools, MSI/EXE payloads dropped by downloaders, and direct operator install after credential compromise. Payload behavior typically creates a client service, connects outbound to vendor relay or attacker-controlled ScreenConnect infrastructure, enables remote desktop, file transfer, command shell and unattended access, and may run under a service context for persistence.

C2 communication: ScreenConnect clients commonly beacon to screenconnect.com, hosted subdomains, self-hosted relay ports, or operator-controlled domains over HTTPS/WebSocket-like sessions. Treat any unexpected ScreenConnect installation, especially launched by Outlook, Chrome, Edge, Teams, Zoom, PowerShell, msiexec or rundll32, as suspicious until validated by change records.

Persistence: Windows services named similar to ScreenConnect Client, ConnectWise, or custom rebranded service names; Run keys; scheduled tasks; and reinstallers dropped in ProgramData, AppData or user-writable directories. Anti-analysis: legitimate signed binaries reduce AV friction; attackers may use access sessions rather than persistent implants, delay connection until operator activity, rename binaries, abuse cloud relays, and remove obvious installer artifacts after setup.

IOC Analysis

The sample indicators are domain and hostname objects, not file hashes. That means the highest-value controls are DNS, proxy, EDR network telemetry, email URL-click logs and identity sign-in analytics rather than hash blocking alone. The listed domains such as furqanmustafa.com, pittni.com, vazquezfleytas.com, edificiocristal.pt and velvorra.com should be blocked and retro-hunted. The hostnames odahlzr5lm.reliabilityinoperations.de and the long .vu service-style hostnames look like disposable or subdomain-heavy infrastructure and are strong candidates for wildcard-aware DNS analytics, entropy scoring and newly observed domain detection.

SOC operationalization: ingest IOCs into a TI platform such as MISP or OpenCTI, push to DNS firewall, secure web gateway, Microsoft Sentinel watchlists, CrowdStrike/Defender custom indicators and email security URL-click retro-search. Keep the Google domains out of blanket blocks; instead alert on sequences where a google.com-family URL is immediately followed by a low-reputation domain, especially if the destination is in the IOC list. Decode URL fragments with CyberChef, Python urllib.parse/urlsplit plus base64url decoding, or a controlled detonation browser to recover embedded victim emails while minimizing privacy exposure. Preserve fragments from email click logs because many proxies never see fragment data after the browser handles it locally.

Detection Engineering

Use these analytics as starting points and tune field names to your pipeline.

YAML
---
title: OTX Google Trust-Proxy Phishing Redirect Chain
id: 9f0b9d2a-5d6f-4f93-a1dd-0txg00gle001
status: experimental
description: Detects web traffic where trusted Google properties are chained with pulse-listed phishing domains or disposable hostnames used for credential harvesting.
author: Security Arsenal
logsource:
  category: proxy
detection:
  selection_google_chain:
    url|contains:
      - 'google.com/search'
      - 'meet.google.com'
      - 'doubleclick.net'
      - 'googletagmanager.com'
      - 'google-analytics.com'
      - 'cse.google.com'
  selection_iocs:
    url|contains:
      - 'furqanmustafa.com'
      - 'pittni.com'
      - 'vazquezfleytas.com'
      - 'edificiocristal.pt'
      - 'velvorra.com'
      - 'odahlzr5lm.reliabilityinoperations.de'
      - 'cloudbemismanufacturingcompanygroup.rydezyhrsysteminc.vu'
      - 'servicetriumphgroupsimplyappraisals.spectrhwqumbrands.vu'
  condition: selection_google_chain and selection_iocs
falsepositives:
  - Legitimate Google marketing redirects and accessibility tools; validate destination domain reputation and click context.
level: high
tags:
  - attack.t1183
  - attack.t1566
  - attack.t1071.001
---
title: Suspicious ScreenConnect Client Execution From Browser or Office Context
id: 7b7f6d2c-4f95-4f1c-9e2b-scrconn002
status: experimental
description: Detects ScreenConnect/ConnectWise client processes launched by browsers, email clients, PowerShell or installer contexts after possible phishing or credential compromise.
author: Security Arsenal
logsource:
  product: windows
  category: process_creation
detection:
  selection_img:
    Image|contains:
      - 'ScreenConnect'
      - 'ConnectWise'
  selection_parent:
    ParentImage|contains:
      - 'chrome'
      - 'msedge'
      - 'OUTLOOK'
      - 'Teams'
      - 'powershell'
      - 'msiexec'
      - 'rundll32'
  selection_unexpected_path:
    Image|contains:
      - 'AppData'
      - 'ProgramData'
      - 'Temp'
      - 'Downloads'
  condition: selection_img and selection_parent and selection_unexpected_path
falsepositives:
  - Approved IT remote support installs; verify ticket, admin account, source URL and signing metadata.
level: critical
tags:
  - attack.t1102
  - attack.t1219
  - attack.t1059
---
title: ScreenConnect Persistence Through Windows Service or Run Key
id: 1ddaf772-5f70-4cb2-bb7f-scrconn003
status: experimental
description: Detects registry persistence events that reference ScreenConnect, ConnectWise or remote access client service artifacts outside approved deployment locations.
author: Security Arsenal
logsource:
  product: windows
  category: registry_set
detection:
  selection_value:
    TargetObject|contains:
      - 'ScreenConnect'
      - 'ConnectWise'
      - 'CurrentVersion\Run'
      - 'Services'
  selection_detail:
    Details|contains:
      - 'ScreenConnect'
      - 'ConnectWise'
      - 'AppData'
      - 'ProgramData'
      - 'Temp'
  condition: selection_value and selection_detail
falsepositives:
  - Managed RMM rollout by IT; compare against software inventory and maintenance windows.
level: high
tags:
  - attack.t1543.003
  - attack.t1547.001
  - attack.t1219
KQL — Microsoft Sentinel / Defender
let bad_iocs = dynamic(["furqanmustafa.com","pittni.com","vazquezfleytas.com","edificiocristal.pt","velvorra.com","odahlzr5lm.reliabilityinoperations.de","cloudbemismanufacturingcompanygroup.rydezyhrsysteminc.vu","servicetriumphgroupsimplyappraisals.spectrhwqumbrands.vu"]);
let google_props = dynamic(["google.com/search","meet.google.com","doubleclick.net","googletagmanager.com","google-analytics.com","cse.google.com"]);
union isfuzzy=true
(
  DeviceNetworkEvents
  | where Timestamp > ago(14d)
  | where RemoteUrl has_any (bad_iocs)
     or (RemoteUrl has_any (google_props) and InitiatingProcessFileName in~ ("chrome.exe","msedge.exe","OUTLOOK.EXE","Teams.exe"))
  | project Timestamp, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl, RemoteIP, ActionType
),
(
  DeviceProcessEvents
  | where Timestamp > ago(14d)
  | where FileName has_any ("ScreenConnect","ConnectWise") or ProcessCommandLine has_any ("ScreenConnect","ConnectWise")
  | project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine, FolderPath, InitiatingProcessFileName, InitiatingProcessCommandLine, SHA256
)
| order by Timestamp desc
PowerShell
$ErrorActionPreference = 'SilentlyContinue'
$iocs = @('furqanmustafa.com','pittni.com','vazquezfleytas.com','edificiocristal.pt','velvorra.com','odahlzr5lm.reliabilityinoperations.de','cloudbemismanufacturingcompanygroup.rydezyhrsysteminc.vu','servicetriumphgroupsimplyappraisals.spectrhwqumbrands.vu')
Write-Host '[+] Services and installed RMM artifacts'
Get-CimInstance Win32_Service | Where-Object { $_.Name -match 'screenconnect|connectwise|remote' -or $_.PathName -match 'screenconnect|connectwise' } | Select-Object Name, DisplayName, State, StartMode, PathName
Write-Host '[+] Run-key persistence'
$runKeys = @('HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run','HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce','HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run','HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce')
foreach ($k in $runKeys) { Get-ItemProperty $k | ForEach-Object { $_.PSObject.Properties | Where-Object { $_.Value -match 'screenconnect|connectwise|appdata|programdata|temp' } | Select-Object Name, Value } }
Write-Host '[+] Scheduled tasks referencing remote access tooling'
Get-ScheduledTask | Where-Object { ($_.TaskName -match 'screenconnect|connectwise') -or ($_.Actions.Execute -match 'screenconnect|connectwise') -or ($_.Actions.Arguments -match 'screenconnect|connectwise') } | Select-Object TaskName, TaskPath, State
Write-Host '[+] DNS cache hits for pulse IOCs'
Get-DnsClientCache | Where-Object { $name = $_.Name; $iocs | ForEach-Object { $name -like ('*' + $_ + '*') } } | Select-Object Name, Type, TimeToLive, Data
Write-Host '[+] Active and recent TCP endpoints resolving toward suspicious RMM or IOC infrastructure'
Get-NetTCPConnection | Where-Object { $_.State -eq 'Established' } | ForEach-Object { $r = $_; try { $dns = Resolve-DnsName $r.RemoteAddress -ErrorAction Stop | Select-Object -First 1 -ExpandProperty Name } catch { $dns = $null }; if ($dns -and (($iocs | ForEach-Object { $dns -like ('*' + $_ + '*') }) -or $dns -match 'screenconnect|connectwise')) { [pscustomobject]@{ LocalAddress=$r.LocalAddress; LocalPort=$r.LocalPort; RemoteAddress=$r.RemoteAddress; RemotePort=$r.RemotePort; RemoteName=$dns; OwningProcess=$r.OwningProcess; Process=(Get-Process -Id $r.OwningProcess).ProcessName } } }
Write-Host '[+] Common writable paths for unexpected ScreenConnect artifacts'
$paths = @($env:ProgramData, $env:LOCALAPPDATA, $env:APPDATA, $env:TEMP, "$env:USERPROFILE\Downloads")
foreach ($p in $paths) { Get-ChildItem $p -Recurse -ErrorAction SilentlyContinue | Where-Object { $_.Name -match 'screenconnect|connectwise' -or $_.FullName -match 'screenconnect|connectwise' } | Select-Object FullName, Length, CreationTime, LastWriteTime }

Response Priorities

Immediate: add the listed domains and hostnames to DNS, proxy, EDR and email click controls; block the two .vu hostnames exactly and alert on sibling subdomains rather than blocking the whole TLD; retro-search 30 to 90 days of DNS, proxy, email URL-click and Defender/Sentinel network telemetry; isolate hosts with unexpected ScreenConnect services; capture volatile data before removing RMM tools; preserve original email headers, rewritten URLs, click timestamps and URL fragments.

24 hours: force password reset and revoke refresh tokens for any user whose encoded email appears in decoded fragments or whose endpoint visited the IOC chain; review Entra ID/Google Workspace/Okta sign-ins for impossible travel, new MFA methods, inbox rules, OAuth grants and session-token reuse; validate whether ScreenConnect access was legitimate by ticket, admin identity, source IP and approval workflow; hunt for inbox-rule creation, Teams/Slack social-engineering follow-up and payment-process changes in finance and government business units.

1 week: implement conditional access and phishing-resistant MFA for targeted sectors; restrict outbound RMM to an approved allowlist and alert on all other remote access clients; add controls that score multi-hop SaaS redirects instead of trusting the first hop; require DNS visibility into newly observed domains and high-entropy subdomains; create a break-glass workflow to rapidly disable unauthorized remote support services; run user coaching for manufacturing, government, finance and NGO staff using the exact trust-proxy lure pattern.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.