GTFire Phishing Campaign Exploits Google Services to Bypass Detection and Harvest Credentials
GTFire is a large-scale phishing scheme exploiting multiple Google services to conceal malicious infrastructure, bypass security tools, and steal credentials from organizations globally.
GTFire is a large-scale phishing scheme exploiting multiple Google services to conceal malicious infrastructure, bypass security tools, and steal credentials from organizations globally.
This credential-harvesting operation utilizes Google Firebase Hosting and Google Translate to create phishing pages resembling legitimate brand logins.
Attackers host fake login portals on Firebase domains and wrap them in translate.goog links. This method leverages Google's trusted reputation to evade email and web filters.
Analysis of the command-and-control infrastructure reveals over 120 phishing domains and credentials stolen from more than 1,000 organizations across 100+ countries and 200+ industries.
Telemetry linked to the GTFire infrastructure indicates a global victim base, with Mexico, the United States, Spain, India, and Argentina among the most impacted countries.
Victims include entities in manufacturing, education, government, and other sectors, demonstrating the campaign's broad targeting strategy. Mexico accounts for 385 victims, followed by 101 in the United States, 67 in Spain, 54 in India, and 50 in Argentina.
This credential-harvesting operation utilizes Google Firebase Hosting and Google Translate to create phishing pages resembling legitimate brand logins.
GTFire employs Firebase's free hosting to rapidly generate and rotate phishing pages, complicating domain-based blocking. These pages load brand-specific templates, utilizing a consistent phishing framework while altering logos and assets to impersonate multiple services.
Google Translate is exploited to deliver translate.goog URLs that proxy the phishing site, concealing the true destination and delaying exposure of the Firebase domain.
Redirects, Obfuscation, and Harvesting
The redirect flow typically begins with a translate.goog link, passes through intermediate domains, and resolves to the final Firebase phishing page.
URL parameters often contain Base64-encoded data encoding victim email addresses, language settings, and brand identifiers, complicating static analysis and detection.
Victims are prompted to enter credentials twice, with a fake error message between attempts, exfiltrating both submissions before redirecting to the legitimate brand site.
Stolen data is transmitted via HTTP GET requests to LiteSpeed Web Server-based C2 hosts running commercial "All-in-1" PHP phishing scripts. This system centralizes data collection, facilitating automated and scalable operations.
Directory listings on these servers show credentials organized by date, language, and targeted service, indicating a mature workflow aimed at account takeover, resale, and secondary fraud.
Defenders should monitor patterns in Firebase subdomain generation, translate.goog redirect chains, Base64-heavy URL parameters, and LiteSpeed/All-in-1 PHP endpoints. Combining these with brand monitoring and user education can help detect and disrupt similar phishing operations exploiting trusted services.
Based on reporting by GBHackers.
