Cybersecuritynews
GTFire Phishing Campaign Exploits Google Services for Credential Theft
First seen 2 Mar 2026, 16:11 UTC
•

•89% similarity
•31.2
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
The GTFire phishing campaign is leveraging Google services, specifically Firebase and Google Translate, to steal login credentials from users globally. By disguising malicious links within trusted Google domains, the campaign effectively bypasses email filters and web security measures, increasing its reach and impact.
ThreatCluster AI
Timeline
2026-03-02
GTFire phishing campaign reported by multiple cybersecurity outlets
Date unknown
Campaign identified as using Google Firebase and Translate
Date unknown
Malicious links evade detection through legitimate Google domains