← All briefs
high October 8, 2026

Final Notice: Google Drive Share Phishing Delivering a GoTo Resolve Remote Access Agent

Source report →

Since mid-September 2026, Vega Threat Research has tracked a phishing campaign delivering debt-collection lures through Google Drive sharing notifications. The operator creates disposable Google accounts, uploads debt-themed documents, and shares them with targeted recipients, who receive standard Google Drive notifications that pass sender-authentication checks. Across five observed waves, sharer display names impersonated at least twenty major law firms, while document titles used payment and account-restriction themes such as overdue balances and final reminders.

The notifications use several techniques that can complicate filtering and clustering. Document titles replace Latin letters with visually similar Cyrillic, Greek, Cherokee, and IPA characters, while randomized plus-tags are appended to recipient addresses so each notification carries a unique recipient string while still reaching the intended mailbox. Sharing accounts also use disposable Reply-To addresses on recently registered domains. One observed notification was sent to roughly two dozen unrelated recipients spanning consumer webmail, a university, a government organization, and several companies.

The shared document contains a button that redirects the victim to a blank page hosted in a randomly named Google Cloud Storage bucket. Within roughly one second, the browser contacts operator-controlled gate infrastructure. One observed gate server was identified as running the Keitaro traffic distribution system, while the remaining servers exhibited the same TDS behavior and are assessed with high confidence to also run Keitaro. Automated or unwanted visitors are frequently redirected to legitimate Yahoo or Google pages, while selected visitors receive a small VBScript saved to the Downloads folder under an e-signature-themed filename.

The VBScript requests administrative privileges, retrieves the location of the next-stage package from a second Google Cloud Storage object, and silently installs an MSI from the user's temporary directory. Subsequent network activity was consistent with the MSI installing a GoTo Resolve agent, giving the operator persistent interactive access through a legitimate, signed remote-management product.

The infrastructure follows a repeatable registration pattern. Reply-To domains were registered in bulk, often within seconds of one another and frequently before related phishing activity appeared in mailboxes, with domains from the same registration cluster sharing Cloudflare nameserver pairs. Gate domains used dyna-ns.net nameservers and resolved directly to dedicated servers without Cloudflare proxying.

DOMAIN 54
importantthingstoknow[.]com
informationreviewcenter[.]com
checkyourimportantinformation[.]com
importantinformationguide[.]com
yourimportantinformation[.]com
importantdocumentsandinformation[.]com
informationyoushouldknow[.]com
importantlettersanddocuments[.]com
essentialinformationandresources[.]com
reviewyourimportantdocuments[.]com
importantthingsandinformation[.]com
importantinformationandupdates[.]com
importantinformationcenter[.]com
documentsreviewurgent[.]com
urgentupdatecenter[.]com
reviewimportantinformation[.]com
updatedocumentsnow[.]com
urgentinforeview[.]com
reviewurgentdocs[.]com
importantdocumentreview[.]com
informationupdatehub[.]com
urgentdocumentsreview[.]com
importantinformationupdate[.]com
urgentdocumentsreview[.]online
importantdocumentreview[.]online
importantinformationupdate[.]online
informationupdatehub[.]online
reviewurgentdocs[.]online
documentupdatecenter[.]com
urgentreviewinformation[.]com
urgentimportantreview[.]com
updateinformationreview[.]com
informationurgentreview[.]com
importantupdatedocuments[.]com
importanturgentdocuments[.]com
documentsupdateurgent[.]com
reviewupdatehub[.]com
importantinformationandnotices[.]com
importantnoticesandupdates[.]com
importantupdateshub[.]com
informationandnotices[.]com
informationupdatesandnotices[.]com
noticesandnotifications[.]com
updatesandimportantinformation[.]com
updatesandnoticeshub[.]com
updatesinformationhub[.]com
secureupdatesandnotices[.]com
primaryofferstage[.]com
limpmnjert[.]com
agentrontris[.]com
importantupdatesandnotices[.]com
updatesandnoticessecure[.]com
inforeviewupdate[.]com
importantnotificationsandupdates[.]com
EMAIL 1
conpafipa1997@review.documentsreviewurgent[.]com
IP ADDRESS 4
172.86.112[.]171
45.61.182[.]129
104.194.155[.]73
45.61.183[.]113
URL 1
https://storage.googleapis[.]com/slim-creek-1228/pure-sky/slim-lake.txt
FILE NAME 1
e-Sign-Key-Access-ID77267361.vbs
SHA256 FILE HASH 1
68b60976d6e46b0a6828670b72b95dfefb8bb1df595d79f22421bb90a716a910

Detections (10)

Enable detections →

Connect your environment for suggestions and queries personalized to your security telemetry.

  • Silent MSI Install From User Writable Path via Script Host or Shell
  • Google Drive Share With Randomized Recipient Suffix
  • Script File Named e-Sign-Key-Access-ID Written or Executed
  • WSH Resolving a Cloud Object Storage Domain
  • Script Self Elevation via Windows Script Host
  • VBScript From the Downloads Folder Followed by a Silent MSI Install
  • GoTo Resolve Remote Access Agent Installed via Silent MSI From Temp
  • Track user clicks on URLs that redirect through multiple domains before payload delivery
  • Alert on VBScript execution from temporary directories or spawned by office applications