Cyber Security News

Threat Actors Using Fake Google Forms Site to Harvest Google Logins

A new phishing campaign is targeting job seekers through fake Google Forms websites designed to steal login credentials.

The campaign uses sophisticated domain impersonation techniques to trick victims into revealing their Google account information.

Attackers have registered a fraudulent domain that closely mimics the legitimate Google Forms service.

The phishing operation revolves around suspicious URLs using the subdomain forms.google.ss-o[.]com, which attempts to impersonate the legitimate forms.google.com address.

The “ss-o” portion appears designed to resemble “single sign-on,” an authentication method that allows users to access multiple applications with one set of credentials. This clever naming choice adds legitimacy to the fake domain.

When victims receive these phishing links through targeted emails or LinkedIn messages, they are directed to what appears to be an authentic Google Forms page.

Fake Google Forms site (Source – Malwarebytes)

The fake form advertises a Customer Support Executive position, requesting applicants to provide their name, email, and explain why they deserve the role.

Malwarebytes analysts identified this campaign during their investigation into job-themed phishing attacks, revealing the extent of this credential harvesting operation.

The attackers implemented redirect mechanisms to prevent security researchers from analyzing their infrastructure. When suspicious URLs were accessed, victims were redirected to local Google search pages.

Technical Infrastructure Behind the Attack

The phishing crew deployed a file called generation_form.php on their domain to create personalized URLs for each victim. This script generates unique links that track individual targets.

The fake website replicates Google Forms design elements, including official logos, color schemes, and the standard disclaimer stating “This content is neither created nor endorsed by Google.”

When victims click the “Sign in” button, they are redirected to id-v4[.]com/generation.php, which has been used in phishing campaigns for nearly a year.

Security experts recommend several protective measures. Never click links in unsolicited job offers, regardless of how legitimate they appear.

Using a password manager provides protection, as these tools will not autofill credentials on fraudulent websites. Implementing real-time anti-malware solutions helps detect and block phishing attempts.

Organizations should educate employees about identifying suspicious domains and verifying job opportunities through official channels.

Enabling multi-factor authentication on Google accounts adds security that prevents unauthorized access even if credentials are stolen.

Indicators of Compromise

DomainStatus
id-v4[.]comTaken down
forms.google.ss-o[.]comActive phishing domain

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

33 minutes ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

10 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

11 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

12 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

12 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

12 hours ago