Threat actors abuse Google AMP for evasive phishing attacks

Teilen:

Security researchers are warning of increased phishing activity that abuses Google Accelerated Mobile Pages (AMP) to bypass email security measures and get to inboxes of enterprise employees.

Google AMP is an open-source HTML framework co-developed by Google and 30 partners to make web content load faster on mobile devices.

AMP pages are hosted on Google’s servers, where content is simplified and some of the heavier media elements are pre-loaded for faster delivery.

The idea behind using Google AMP URLs embedded in phishing emails is to make sure that email protection technology does not flag messages as malicious or suspicious due to Google’s good reputation.

The AMP URLs trigger a redirection to a malicious phishing site, and this additional step also adds an analysis-disrupting layer.

Google AMP redirection to a phishing site
Google AMP redirection to a phishing site (Cofense)

Data from anti-phishing protection company Cofense shows that the volume of phishing attacks employing AMP spiked spiked significantly towards mid-July, suggesting that threat actors may be adopting the method.

Phishing emails abusing Google AMP
Phishing emails leveraging Google AMP for stealth (Cofense)

“Out of all the Google AMP URLs we have observed, approximately 77% were hosted on the domain google.com, and 23% were hosted on the domain google.co.uk,” explains Cofense in the report.

Although the “google.com/amp/s/” path is common in all cases, blocking this would also impact all legitimate cases of using Google AMP. However, flagging them may be the most appropriate action, to at least alert recipients to be wary of potentially malicious redirections.

Extra stealth

Cofense says the phishing actors who abuse the Google AMP service also employ a range of additional techniques that collectively help evade detection and increase their success rate.

For example, in many cases observed by Cofense, the threat actors used image-based HTML emails instead of a traditional text body. This is to confuse text scanners that look for common phishing terms in the message content.

Image-based phishing email
Image-based phishing email (Cofense)

In another example, the attackers used an extra redirection step, abusing a Microsoft.com URL to take the victim to a Google AMP domain and eventually to the actual phishing site.

Microsoft redirection to a Google AMP site
Microsoft redirection to a Google AMP site (Cofense)

Finally, attackers employed Cloudflare’s CAPTCHA service to thwart automated analysis of the phishing pages by security bots, preventing the crawlers from reaching them.

All in all, phishing actors today employ multiple detection-evading methods that make it increasingly difficult for targets and security tools to catch the threats and block them.

 

(c) Lawrence Abrams

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
9:25 am, Mai 19, 2025
Wetter-Symbol 13°C
L: 12° | H: 14°
overcast clouds
Luftfeuchtigkeit: 75 %
Druck: 1021 mb
Wind: 6 mph NE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 5:02 am
Sonnenuntergang: 8:51 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
12° | 14°°C 0 mm 0% 12 mph 78 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
10° | 22°°C 0 mm 0% 10 mph 67 % 1022 mb 0 mm/h
Mi. Mai 21 10:00 pm
Wetter-Symbol
13° | 21°°C 0.2 mm 20% 9 mph 64 % 1020 mb 0 mm/h
Do. Mai 22 10:00 pm
Wetter-Symbol
11° | 18°°C 0 mm 0% 11 mph 64 % 1023 mb 0 mm/h
Fr. Mai 23 10:00 pm
Wetter-Symbol
7° | 18°°C 0.7 mm 70% 11 mph 77 % 1023 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
12° | 14°°C 0 mm 0% 8 mph 78 % 1021 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
14° | 18°°C 0 mm 0% 9 mph 67 % 1021 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
17° | 19°°C 0 mm 0% 12 mph 52 % 1020 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
17° | 17°°C 0 mm 0% 10 mph 46 % 1020 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
13° | 13°°C 0 mm 0% 7 mph 61 % 1021 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
10° | 10°°C 0 mm 0% 5 mph 66 % 1022 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
10° | 10°°C 0 mm 0% 6 mph 67 % 1021 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 7 mph 63 % 1022 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,223.37
-0.70%
Ethereum(ETH)
€2,151.88
-4.35%
Fesseln(USDT)
€0.89
0.00%
XRP(XRP)
€2.06
-3.92%
Solana(SOL)
€144.59
-5.42%
USDC(USDC)
€0.89
0.00%
Dogecoin(DOGE)
€0.194167
-2.57%
Shiba Inu(SHIB)
€0.000013
-4.17%
Pepe(PEPE)
€0.000012
-1.24%
Peanut das Eichhörnchen(PNUT)
€0.284768
-9.77%
Nach oben scrollen