Final Notice: Google Drive Share Phishing Delivering a GoTo Resolve Remote Access Agent
Source report →Since mid-September 2026, Vega Threat Research has tracked a phishing campaign delivering debt-collection lures through Google Drive sharing notifications. The operator creates disposable Google accounts, uploads debt-themed documents, and shares them with targeted recipients, who receive standard Google Drive notifications that pass sender-authentication checks. Across five observed waves, sharer display names impersonated at least twenty major law firms, while document titles used payment and account-restriction themes such as overdue balances and final reminders.
The notifications use several techniques that can complicate filtering and clustering. Document titles replace Latin letters with visually similar Cyrillic, Greek, Cherokee, and IPA characters, while randomized plus-tags are appended to recipient addresses so each notification carries a unique recipient string while still reaching the intended mailbox. Sharing accounts also use disposable Reply-To addresses on recently registered domains. One observed notification was sent to roughly two dozen unrelated recipients spanning consumer webmail, a university, a government organization, and several companies.
The shared document contains a button that redirects the victim to a blank page hosted in a randomly named Google Cloud Storage bucket. Within roughly one second, the browser contacts operator-controlled gate infrastructure. One observed gate server was identified as running the Keitaro traffic distribution system, while the remaining servers exhibited the same TDS behavior and are assessed with high confidence to also run Keitaro. Automated or unwanted visitors are frequently redirected to legitimate Yahoo or Google pages, while selected visitors receive a small VBScript saved to the Downloads folder under an e-signature-themed filename.
The VBScript requests administrative privileges, retrieves the location of the next-stage package from a second Google Cloud Storage object, and silently installs an MSI from the user's temporary directory. Subsequent network activity was consistent with the MSI installing a GoTo Resolve agent, giving the operator persistent interactive access through a legitimate, signed remote-management product.
The infrastructure follows a repeatable registration pattern. Reply-To domains were registered in bulk, often within seconds of one another and frequently before related phishing activity appeared in mailboxes, with domains from the same registration cluster sharing Cloudflare nameserver pairs. Gate domains used dyna-ns.net nameservers and resolved directly to dedicated servers without Cloudflare proxying.
IOCs (62)
Scan your environment for IOCs →DOMAIN 54
importantthingstoknow[.]cominformationreviewcenter[.]comcheckyourimportantinformation[.]comimportantinformationguide[.]comyourimportantinformation[.]comimportantdocumentsandinformation[.]cominformationyoushouldknow[.]comimportantlettersanddocuments[.]comessentialinformationandresources[.]comreviewyourimportantdocuments[.]comimportantthingsandinformation[.]comimportantinformationandupdates[.]comimportantinformationcenter[.]comdocumentsreviewurgent[.]comurgentupdatecenter[.]comreviewimportantinformation[.]comupdatedocumentsnow[.]comurgentinforeview[.]comreviewurgentdocs[.]comimportantdocumentreview[.]cominformationupdatehub[.]comurgentdocumentsreview[.]comimportantinformationupdate[.]comurgentdocumentsreview[.]onlineimportantdocumentreview[.]onlineimportantinformationupdate[.]onlineinformationupdatehub[.]onlinereviewurgentdocs[.]onlinedocumentupdatecenter[.]comurgentreviewinformation[.]comurgentimportantreview[.]comupdateinformationreview[.]cominformationurgentreview[.]comimportantupdatedocuments[.]comimportanturgentdocuments[.]comdocumentsupdateurgent[.]comreviewupdatehub[.]comimportantinformationandnotices[.]comimportantnoticesandupdates[.]comimportantupdateshub[.]cominformationandnotices[.]cominformationupdatesandnotices[.]comnoticesandnotifications[.]comupdatesandimportantinformation[.]comupdatesandnoticeshub[.]comupdatesinformationhub[.]comsecureupdatesandnotices[.]comprimaryofferstage[.]comlimpmnjert[.]comagentrontris[.]comimportantupdatesandnotices[.]comupdatesandnoticessecure[.]cominforeviewupdate[.]comimportantnotificationsandupdates[.]comEMAIL 1
conpafipa1997@review.documentsreviewurgent[.]comIP ADDRESS 4
172.86.112[.]17145.61.182[.]129104.194.155[.]7345.61.183[.]113URL 1
https://storage.googleapis[.]com/slim-creek-1228/pure-sky/slim-lake.txtFILE NAME 1
e-Sign-Key-Access-ID77267361.vbsSHA256 FILE HASH 1
68b60976d6e46b0a6828670b72b95dfefb8bb1df595d79f22421bb90a716a910Detections (10)
Enable detections →Connect your environment for suggestions and queries personalized to your security telemetry.
- Silent MSI Install From User Writable Path via Script Host or Shell
- Google Drive Share With Randomized Recipient Suffix
- Script File Named e-Sign-Key-Access-ID Written or Executed
- WSH Resolving a Cloud Object Storage Domain
- Script Self Elevation via Windows Script Host
- VBScript From the Downloads Folder Followed by a Silent MSI Install
- GoTo Resolve Remote Access Agent Installed via Silent MSI From Temp
- Track user clicks on URLs that redirect through multiple domains before payload delivery
- Alert on VBScript execution from temporary directories or spawned by office applications