Cyber Security News

Google’s New Search Redirects Make It Harder to Check Where Links Lead Before Clicking

Google is changing how some search-result links behave. Certain results now pass through an encoded Google redirect rather than opening the listed site, making a browser’s link preview less useful as a quick safety check.

The change comes as malicious advertising, search-result poisoning, and lookalike download pages keep turning ordinary searches into routes for scams and malware.

Users may still see a familiar site name in the result, but their ability to compare that label with the actual link has weakened at the moment they decide whether to click.

Analysts at Malwarebytes noted that the rollout uses opaque google.com/goto?url= redirects whose url parameter contains a custom Google-specific encoding instead of a readable destination.

This is not a newly discovered malware family or a confirmed attack campaign, but it changes a basic browsing habit used to spot suspicious links.

Google says it deploys technical measures against evolving abuse, but has not specified the reason for this change. The apparent effect is to make large-scale extraction of result destinations harder because automated tools must resolve each redirect separately.

Malwarebytes said in a report shared with Cyber Security News (CSN) that the final destination is viewable only through the redirect response’s Location header. The extra request affects bulk scrapers and legitimate research, archiving, accessibility, rank tracking, and audit tools.

Google’s New Search Redirects Make It Harder

For years, standard safety advice has been to hover over a search result and inspect the address displayed by the browser before clicking.

That check can expose a misspelled domain, unrelated host, or suspicious path. Under the new system, the preview may show an encoded Google address rather than the website a user expects to visit.

Google still displays the claimed destination above the result, but that label is no longer independently confirmed by the link preview.

The distinction matters because attackers use search pages to make harmful destinations look ordinary. Recent campaigns abusing hijacked Google Ads accounts have sent users to clone sites and malware downloads after misleading sponsored listings.

This does not mean every goto redirect is malicious, or prove that Google is directing users to unsafe pages. It does mean a familiar visual check offers less assurance.

Google built its search business by automatically collecting information from other websites (SOurce – Malwarebytes)

A result title, displayed domain, or redirect address should not be treated as proof that a download page or sign-in request is legitimate.

The risk is sharper for searches involving software, technical support, banking, or account recovery. Criminals can buy or compromise advertising placements and create pages that closely copy trusted brands.

Reporting on poisoned search result campaigns shows how high-ranking links can lead to fraudulent banking pages that capture passwords and active sessions.

Safer Ways to Verify Results

Users should take an extra moment before opening sensitive results, especially sponsored entries. Rather than relying on hover text alone, type a known official address, use a saved bookmark, or navigate from a verified company profile.

For software, reach the publisher’s site directly instead of following an ad or a result promising an urgent update. If a page asks for credentials, payment data, a browser extension, or a command to paste into a terminal, stop and verify through another route.

This matters when a search leads to a support page or installer. A recent fake Node.js installer campaign used sponsored results to lure Windows users toward an infostealer.

Organizations that collect search data should expect more requests, possible rate limits, and added cost when resolving destinations.

Security teams can update awareness guidance: hovering remains useful in many contexts, but it may not disclose the final target of these results. Staff should validate high-risk links through trusted navigation paths.

The broader lesson is that search results are not a security boundary. Redirects may be intended to curb automated abuse, but they remove a layer of transparency from everyday browsing.

As attacks using trusted Google service routes show, familiar infrastructure can be part of a convincing chain, making independent verification more important before users click.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
URL patterngoogle.com/goto?url=...Encoded Google Search redirect URL pattern described in the source material.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

49 minutes ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

11 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

12 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

12 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

12 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

12 hours ago