GTFire Phishing Scheme Abuses Google Services to Evade Detection and Steal Credentials
A recent phishing campaign, referred to as GTFire, exploits Google's Firebase and Google Translate services to collect login credentials from users globally.
A recent phishing campaign, referred to as GTFire, exploits Google's Firebase and Google Translate services to collect login credentials from users globally.
The GTFire campaign leverages Google's domains to mask its malicious activities. This tactic allows phishing links to evade detection by email filters and web security systems.
Victims are directed to deceptive login pages mimicking legitimate brands. After submission of credentials, users are redirected to the actual brand's website, unaware of the security breach.
The campaign has affected thousands of credentials across over 1,000 organizations in more than 100 countries, involving over 200 industries. Mexico has the highest number of confirmed victims, primarily in manufacturing, education, and government sectors, followed by the United States, Spain, India, and Argentina.
Group-IB analysts have identified this as a large-scale credential harvesting operation.
The GTFire campaign leverages Google's domains to mask its malicious activities.
The attackers utilize phishing templates with minimal modifications across different brand targets. Stolen data is systematically organized by date, language, and targeted service on centralized servers.
Over 120 unique phishing domains have been identified, using consistent naming patterns to facilitate rapid infrastructure changes.
Phishing pages mimic authentic login portals, making detection difficult. After credential submission, users are redirected to the legitimate brand site, delaying detection of the breach.
The attack begins with a phishing message containing a Google Translate link, which routes through Google's infrastructure to a Firebase-hosted phishing page. This method bypasses email security and web filters.
Firebase hosts multiple phishing pages using dynamically loaded brand-specific elements. Credentials are captured using a reusable framework, with entries sent to attacker-controlled C2 servers via HTTP GET requests. The backend uses commercially available tools to streamline operations.
Organizations should adopt phishing-resistant multi-factor authentication and educate employees about Google-based phishing tactics. Security teams should implement detection rules for URL patterns involving translate.goog and *.web.app domains, and monitor cloud platforms for brand impersonation.
Sharing indicators of compromise, such as network and file-based IOCs, with CERT communities is crucial to mitigating this threat.
Based on reporting by Cyber Security News.
