GTFire is a threat actor abusing Google Firebase and Translate services for phishing campaigns.
Analyst brief
GTFire is a threat actor of unknown type. It primarily targets a broad range of users by abusing legitimate services. Key TTPs include leveraging Google Firebase for hosting phishing pages, using Google Translate to disguise malicious URLs, implementing a multi-step redirect chain, employing All-in-1 PHP phishing scripts for rapid deployment, and exfiltrating credentials via HTTP GET requests. Defenders should focus on monitoring for unusual redirect chains, traffic passing through translate.google.com, suspicious Firebase hosting domains, and the transmission of sensitive data within GET parameters.
GTFire
unknown
GTFire is a threat actor that leverages Google Firebase for hosting phishing pages and Google Translate to disguise malicious URLs, effectively bypassing security filters. The campaign employs a multi-step redirect chain to obscure the final phishing destination and utilizes All-in-1 PHP phishing scripts for rapid deployment and credential harvesting. Credentials are exfiltrated via URL parameters in a standard HTTP GET request, with minimal operational overhead.