Key findings
- Since mid-September, five waves of debt-themed lures have arrived as legitimate Google Drive share notifications impersonating law firms.
- Homoglyph titles, randomized plus-addressing, and disposable Reply-To domains defeat exact-match filtering and clustering.
- A Google Cloud Storage page and a Keitaro TDS send scanners to a decoy and select victims to a VBScript that silently installs GoTo Resolve.
- Reply-To domains are registered in bulk days before use, so the next cluster can be blocked in advance.
- Vega customers are protected. Seven detections cover the chain from share notification to RMM install, and the email detection caught all five waves with no false positives.
Since mid-September 2026, Vega Threat Research has been tracking a phishing campaign that abuses legitimate Google Drive share notifications to deliver debt-themed lures. Victims receive a genuine Google Drive sharing notification for a document the attacker uploaded, with the sharer’s display name and the document title chosen to pressure them into opening it and following the embedded link.
Across five observed waves, the operator paired homoglyph-heavy document titles and disposable Reply-To domains with a delivery chain that runs through Google Cloud Storage and a Keitaro traffic distribution system (TDS), which routes each visitor by configurable rules so that scanners see a decoy while selected victims receive the payload.
The operator also registered infrastructure in repeatable clusters, allowing likely campaign domains to be identified before they were used in phishing activity and giving defenders an opportunity to monitor or block them in advance.
The lure
The operator creates a disposable Google account, uploads a document, and shares it with the target. The recipient then receives a standard Google Drive notification, sent by Google from its own drive-shares address, so the message passes SPF, DKIM, and DMARC and carries the appearance and authentication properties of legitimate Google mail.
The attacker controls the sharer’s display name and the document title, and they carry the social engineering:
- Sharer display name: names impersonating major law firms. We observed at least 20 impersonated firms, rendered here as they appeared with homoglyph characters preserved, including Kirkland & Ellis, Lаthаm & Wаtkins, Skаddеn, Ѕullivan & Ꮯromwell and Dаvɪs Pоlk.
- Document title: used as the email subject, with examples including
[А Dеbt Lеttеr Аrrivеd] -> Pаy!andFinаl Rеmindеr - Аccоunt Blоckаgе.
Beyond the lure text, the operator varied the messages to defeat exact-match filtering and campaign clustering.
Homoglyph substitution. Titles replaced Latin characters with visually similar Cyrillic, Greek, Cherokee, or IPA characters. To a recipient, words such as “debt,” “payment,” or “account” still look normal, but filters relying on exact keyword matches may fail to recognize them.
Random plus-addressing. Recipients were addressed using randomized plus-tags such as user+ufsjc471@company.com. Mail platforms deliver plus-addressed mail to the base mailbox, so the messages still arrive, while each notification carries a distinct recipient string that may complicate message clustering and exact-match detection.
Disposable Reply-To domains. Sharing accounts used addresses such as conpafipa1997@review.documentsreviewurgent[.]com, combining disposable mailbox names with recently registered domains.
One notification observed in our telemetry was sent to roughly two dozen unrelated recipients, spanning consumer webmail, a university, a government organization, and several companies.
From Google Drive to a gated payload
The attack chain continues when the recipient opens the shared document and clicks the embedded button, which redirects them away from Google Drive and into the operator-controlled delivery flow.
An ANY.RUN sandbox session captured on October 2 showed the following delivery chain:
Nothing executes on the endpoint until the chain has passed through Google Cloud Storage, a traffic gate, and the VBScript download:
1. Google Cloud Storage
The first external stage is a blank HTML page hosted in a randomly named Google Cloud Storage bucket, generally following an adjective-noun-number pattern such as calm-ocean-6785. In observed sessions, the page contacted the operator-controlled gate roughly one second after loading, without additional user interaction. Some URLs also contained per-visit tokens in the fragment or query string, suggesting client-side logic may process the token and initiate the next request.
2. Traffic gate
After the Cloud Storage page loads, the browser contacts infrastructure controlled by the operator. We identified one of the gate servers as running Keitaro based on campaign cookies matching Keitaro’s e3b0c4_<id> pattern. The server also used short campaign paths that redirected automated visitors to legitimate destinations, behavior consistent with a traffic distribution system. Supporting characteristics included a default nginx/1.24.0 404 response and a certificate with CN=0.0.0.0.
The remaining gate servers showed the same TDS-style redirection behavior and shared the same supporting fingerprints, including the default nginx/1.24.0 404 page and certificates using CN=0.0.0.0. Although we did not observe a Keitaro-specific artifact such as the e3b0c4_<id> cookie on those servers, the consistency in behavior and server configuration across the campaign leads us to assess with high confidence that they used the same Keitaro-based setup.
The gate frequently sent automated sessions to legitimate destinations such as Yahoo or Google, limiting what scanners and automated analysis systems could observe while selected visitors continued to the payload-delivery path.
3. VBScript delivery
For selected visits, the gate returned a 1,627-byte VBScript file instead of a decoy destination. In the recorded ANY.RUN session, the file was saved to the user’s Downloads directory under a name matching e-Sign-Key-Access-ID<digits>.vbs.
The lure reinforces this handoff by telling the recipient that a valid “E-Signature Key” is required to view the full collection letter, matching the downloaded filename and likely encouraging the victim to open the file.
The VBScript installs a remote-access agent
If opened, the VBScript requests administrative privileges, retrieves a second-stage URL from another Google Cloud Storage object, and silently installs an MSI package.
If the script is not already elevated, it relaunches itself through wscript.exe and triggers a UAC prompt. Once elevated, it retrieves:
storage.googleapis[.]com/slim-creek-1228/pure-sky/slim-lake.txtThe Cloud Storage object contains a URL for the next-stage package, allowing the operator to change the downloaded MSI without modifying the VBScript itself.
The script saves the package as %TEMP%\update.msi and installs it silently using:
msiexec /i "%TEMP%\update.msi" /qn /norestartSubsequent connections to several gotoresolve.com endpoints were consistent with the MSI installing a GoTo Resolve agent. GoTo Resolve is a legitimate remote-support and remote-management platform, and its installation would provide the operator with persistent interactive access through a signed commercial RMM tool rather than a custom RAT.
The resulting delivery chain is shown in Figure 1.
Infrastructure patterns exposed upcoming activity
The campaign’s Reply-To infrastructure showed a repeatable registration pattern.
Using Validin, we discovered that domains were registered in bulk, often within seconds of one another, and frequently before the corresponding phishing activity appeared in mailboxes. Domains from the same registration cluster also shared Cloudflare nameserver pairs.
The gate domains used dyna-ns.net nameservers and resolved directly to dedicated servers, with no Cloudflare proxying in front of them.
What should defenders do?
- Alert on Google Drive share notifications whose document title or sharer display name mixes Unicode scripts, and on notifications addressed to plus-tagged variants of mailboxes that no internal system uses. Both signals survive domain rotation.
- Restrict Windows Script Host where business requirements permit, or at minimum alert when wscript.exe or cscript.exe runs a .vbs file from a Downloads directory. The endpoint chain cannot start without it.
- Alert on msiexec.exe installing a package from %TEMP% with silent flags, and inventory remote-management agents so that a GoTo Resolve installation not deployed by IT is treated as an incident rather than an inventory discrepancy.
- On an affected host, uninstall the GoTo Resolve agent and remove its service, then review activity from the installation time forward for interactive sessions, credential access, and lateral movement. The agent gives the operator the same access a support technician would have.
How Vega customers are protected
Vega customers are protected by seven detections that cover the campaign from the share notification to the installation of the remote-management agent, so coverage does not depend on infrastructure the operator rotates between waves.
At the email stage, two detections identify the campaign’s recurring message-level characteristics:
- Google Drive Share With Randomized Recipient Suffix, Detects delivered Google Drive share notifications sent to recipient addresses containing randomized plus-tags, a pattern used across the campaign to give each message a distinct recipient string.
- Google Drive Share With Homoglyph-Obfuscated Title, Detects delivered Google Drive share notifications whose subject mixes Latin characters with visually similar characters from other scripts, such as Cyrillic, Greek, Cherokee, or IPA.
Together, these detections identified all five observed waves across seven organizations and four email-security vendors over approximately 30 days, with no observed false positives.
On the endpoint, additional detections cover:
- Script File Named e-Sign-Key-Access-ID Written or Executed, identifying .vbs files matching the campaign’s e-Sign-Key-Access-ID<digits>.vbs naming pattern when written to disk or executed.
- Windows Script Host Resolving a Cloud Object Storage Domain, detecting wscript.exe or cscript.exe resolving cloud object storage domains, consistent with a script retrieving hosted content or a next-stage pointer.
- Script Self Elevation via Windows Script Host, detecting scripts relaunched through wscript.exe with the /elevated argument.
- VBScript from the Downloads Folder Followed by a Silent MSI Install, correlating VBScript execution from Downloads with msiexec.exe installing an MSI from %TEMP% using silent-install flags.
- GoTo Resolve Remote Access Agent Installed via Silent MSI From Temp, correlating a silent MSI installation from %TEMP% with subsequent DNS activity to GoTo Resolve infrastructure.
Customers also receive a linked threat brief that brings together these detections, investigation context, and the indicators listed below. Vega scans the indicators automatically against customer data, so teams see current exposure and earlier activity involving the Reply-To domains, Cloud Storage buckets, gate domains, and servers in this report.
MITRE ATT&CK
- T1585.003 Establish Accounts: Cloud Accounts. Disposable Google accounts used to create and share the lure documents.
- T1583.001 Acquire Infrastructure: Domains. Reply-To and gate domains registered in clusters.
- T1583.006 Acquire Infrastructure: Web Services. Google Cloud Storage used to host the redirect page and second-stage pointer.
- T1608.005 Stage Capabilities: Link Target. Cloud Storage HTML page staged as part of the phishing delivery chain.
- T1566.002 Phishing: Spearphishing Link. Google Drive shares notifications direct recipients to attacker-created documents containing the malicious link.
- T1684.001 Social Engineering: Impersonation. Sharer display names impersonate major law firms.
- T1204.001 User Execution: Malicious Link. The victim clicks the embedded button in the shared document.
- T1204.002 User Execution: Malicious File. Victim opens the downloaded VBScript.
- T1059.005 Command and Scripting Interpreter: Visual Basic. VBScript executes through Windows Script Host.
- T1105 Ingress Tool Transfer. The next-stage MSI is downloaded to the endpoint.
- T1218.007 System Binary Proxy Execution: Msiexec. Msiexec silently installs the downloaded MSI using /qn /norestart.
- T1219.002 Remote Access Tools: Remote Desktop Software. GoTo Resolve is installed to provide persistent interactive remote access.
Indicators of Compromise
Reply-To domains
September 15 registration cluster
importantthingstoknow[.]cominformationreviewcenter[.]comcheckyourimportantinformation[.]comimportantinformationguide[.]comyourimportantinformation[.]comimportantdocumentsandinformation[.]cominformationyoushouldknow[.]comimportantlettersanddocuments[.]comessentialinformationandresources[.]comreviewyourimportantdocuments[.]comimportantthingsandinformation[.]comimportantinformationandupdates[.]comimportantinformationcenter[.]com
September 28 registration cluster
documentsreviewurgent[.]comurgentupdatecenter[.]comreviewimportantinformation[.]comupdatedocumentsnow[.]comurgentinforeview[.]comreviewurgentdocs[.]comimportantdocumentreview[.]cominformationupdatehub[.]comurgentdocumentsreview[.]comimportantinformationupdate[.]comurgentdocumentsreview[.]onlineimportantdocumentreview[.]onlineimportantinformationupdate[.]onlineinformationupdatehub[.]onlinereviewurgentdocs[.]online
October 1 registration cluster
documentupdatecenter[.]comurgentreviewinformation[.]comurgentimportantreview[.]comupdateinformationreview[.]cominformationurgentreview[.]comimportantupdatedocuments[.]comimportanturgentdocuments[.]comdocumentsupdateurgent[.]comreviewupdatehub[.]com
October 3 registration cluster
importantinformationandnotices[.]comimportantnoticesandupdates[.]comimportantupdateshub[.]cominformationandnotices[.]cominformationupdatesandnotices[.]comnoticesandnotifications[.]comupdatesandimportantinformation[.]comupdatesandnoticeshub[.]comupdatesinformationhub[.]comsecureupdatesandnotices[.]com
Google Cloud Storage buckets
keen-pine-8764glad-pearl-8755glad-cloud-9402green-pine-3734gold-ember-8348rare-cedar-8642live-heron-4554deep-heron-8389keen-marsh-3698open-birch-7636bright-marsh-1305fresh-olive-9937cool-pearl-5158warm-maple-2464kind-haven-6298kind-maple-2713safe-maple-9478soft-heron-4970calm-ocean-6785wide-cloud-4098
Gate domains / second-stage infrastructure
primaryofferstage[.]comlimpmnjert[.]comagentrontris[.]comimportantupdatesandnotices[.]comupdatesandnoticessecure[.]cominforeviewupdate[.]comimportantnotificationsandupdates[.]com172.86.112[.]171104.194.141[.]5545.61.182[.]129104.194.155[.]7345.61.183[.]113
VBS payload
File name
e-Sign-Key-Access-ID77267361.vbs
SHA256
68b60976d6e46b0a6828670b72b95dfefb8bb1df595d79f22421bb90a716a910
Conclusion
This campaign succeeds without a spoofed sender, a malicious attachment, or a lookalike login page. Google delivers the lure, Google Cloud Storage hosts the first hop and the second-stage pointer, a commercial traffic distribution system decides who receives the payload, and a legitimate RMM agent provides the access. Each piece is benign on its own, which is why the durable signals are the ones the operator cannot change without breaking the attack: the homoglyph titles and randomized plus-tags in the notification, and the script host, msiexec, and remote-management install sequence on the endpoint.
Vega customers are protected across that chain by the seven detections described above. The bulk registration pattern also gives defenders a window to monitor or block the next cluster of domains before it is used. Detection queries, hunting ideas, and a summary of this campaign are at the Vega Threat Hub (https://threats.vega.io/brief).