GTFire Phishing Campaign Exploits Google Services for Credential Theft

GTFire Phishing Campaign Exploits Google Services for Credential Theft

First seen 2 Mar 2026, 16:11 UTC GbhackersCybersecuritynewsCyberpress 89% similarity 31.2

Article Content

Browse articles
ThreatCluster

The GTFire phishing campaign is leveraging Google services, specifically Firebase and Google Translate, to steal login credentials from users globally. By disguising malicious links within trusted Google domains, the campaign effectively bypasses email filters and web security measures, increasing its reach and impact.

ThreatCluster AI

Timeline

2026-03-02
GTFire phishing campaign reported by multiple cybersecurity outlets
Date unknown
Campaign identified as using Google Firebase and Translate
Date unknown
Malicious links evade detection through legitimate Google domains

Community

Browse all →