{"id":41329,"date":"2026-02-18T08:38:53","date_gmt":"2026-02-18T08:38:53","guid":{"rendered":"http:\/\/localhost\/?p=41329"},"modified":"2026-02-18T08:38:53","modified_gmt":"2026-02-18T08:38:53","slug":"job-scam-uses-fake-google-forms-site-to-harvest-google-logins","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=41329","title":{"rendered":"Job scam uses fake Google Forms site to harvest Google logins_MALWAREBYTES:1335B3D719E0A34DEC79C0CBFF0F266E"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-02-18T14:25:24&#8243;,&#8221;description&#8221;:&#8221;As part of our investigation into a job-themed phishing campaign, we came across several suspicious URLs that all looked like this:\\n\\n`https:\/\/forms.google.ss-o[.]com\/forms\/d\/e\/{unique_id}\/viewform?form=opportunitysec\\u0026promo=`\\n\\nThe subdomain `forms.google.ss-o[.]com` is a clear attempt to impersonate the legitimate forms.google.com. The \\&#8221;ss-o\\&#8221; is likely introduced to look like \u201csingle sign-on,\u201d an authentication method that allows users to securely log in to multiple, independent applications or websites using one single set of credentials (username and password).\\n\\nUnfortunately, when we tried to visit the URLs we were redirected to the local Google search website. This is a common phisher\u2019s tactic to prevent victims from sharing their personalized links with researchers or online analysis.\\n\\nAfter some digging, we found a file called `generation_form.php` on the same domain, which we believe the phishing crew used to create these links. The landing page for the campaign was: `https:\/\/forms.google.ss-o[.]com\/generation_form.php?form=opportunitysec`\\n\\nThe `generation_form.php` script does what the name implies: It creates a personalized URL for the person clicking that link.\\n\\nWith that knowledge in hand, we could check what the phish was all about. Our personalized link brought us to this website:\\n\\n![Fake Google Forms site](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2026\/02\/full_website.png)Fake Google Forms site\\n\\nThe greyed out \\&#8221;form\\&#8221; behind the prompt promises:\\n\\n  * We&#8217;re Hiring! Customer Support Executive (International Process)\\n  * Are you looking to kick-start or advance your career\u2026\\n  * The fields in the form: Full Name, Email address, and an essay field \u201cPlease describe in detail why we should choose you\u201d\\n  * Buttons: \u201cSubmit\u201d and \u201cClear form.\u201d\\n\\n\\n\\nThe whole web page emulates Google Forms, including logo images, color schemes, a notice about not \u201csubmitting passwords,\u201d and legal links. At the bottom, it even includes the typical Google Forms disclaimer (\u201cThis content is neither created nor endorsed by Google.\u201d) for authenticity.\\n\\nClicking the \u201cSign in\u201d button took us to `https:\/\/id-v4[.]com\/generation.php`, which has now been taken down. The domain id-v4.com has been used in several phishing campaigns for almost a year. In this case, it asked for Google account credentials.\\n\\nGiven the \u201cjob opportunity\u201d angle, we suspect links were distributed through targeted emails or LinkedIn messages.\\n\\n## How to stay safe\\n\\nLures that promise remote job opportunities are very common these days. Here are a few pointers to help keep you safe from targeted attacks like this:\\n\\n  * Do not click on links in unsolicited job offers.\\n  * Use a password manager, which would not have filled in your Google username and password on a fake website.\\n  * Use an up to date, real-time anti-malware solution with a web protection component.\\n\\n\\n\\nPro tip: Malwarebytes Scam Guard identified this attack as a scam just by looking at the URL.\\n\\n## IOCs\\n\\nid-v4[.]com\\n\\nforms.google.ss-o[.]com\\n\\n![forms.google.ss-o.com blocked by Malwarebytes](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2026\/02\/blocked_by_MBAM.png)Blocked by Malwarebytes\\n\\n* * *\\n\\n**We don &#8216;t just report on scams\u2014we help detect them**\\n\\nCybersecurity risks should never spread beyond a headline. If something looks dodgy to you, check if it&#8217;s a scam using Malwarebytes Scam Guard. Submit a screenshot, paste suspicious content, or share a link, text or phone number, and we\u2019ll tell you if it&#8217;s a scam or legit. Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.&#8221;,&#8221;published&#8221;:&#8221;2026-02-18T12:22:22&#8243;,&#8221;modified&#8221;:&#8221;2026-02-18T12:22:22&#8243;,&#8221;type&#8221;:&#8221;malwarebytes&#8221;,&#8221;title&#8221;:&#8221;Job scam uses fake Google Forms site to harvest Google logins&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;MALWAREBYTES:1335B3D719E0A34DEC79C0CBFF0F266E&#8221;,&#8221;bulletinFamily&#8221;:&#8221;blog&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[],&#8221;sourceData&#8221;:&#8221;&#8221;,&#8221;sourceHref&#8221;:&#8221;&#8221;,&#8221;cvss&#8221;:{&#8220;score&#8221;:0,&#8221;severity&#8221;:&#8221;NONE&#8221;,&#8221;vector&#8221;:&#8221;NONE&#8221;,&#8221;version&#8221;:&#8221;NONE&#8221;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/www.malwarebytes.com\/blog\/scams\/2026\/02\/job-scam-uses-fake-google-forms-site-to-harvest-google-logins&#8221;,&#8221;category_name&#8221;:&#8221;News&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-02-18T14:25:24&#8243;,&#8221;description&#8221;:&#8221;As part of our investigation into a job-themed phishing campaign, we came across several suspicious URLs that all looked like this:\\n\\n`https:\/\/forms.google.ss-o[.]com\/forms\/d\/e\/{unique_id}\/viewform?form=opportunitysec\\u0026promo=`\\n\\nThe subdomain `forms.google.ss-o[.]com` is a&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[6,8,12,115,13,33,7,11,5],"class_list":["post-41329","post","type-post","status-publish","format-standard","hentry","category-category_news","tag-cve","tag-cvss","tag-exploit","tag-malwarebytes","tag-news","tag-none","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Job scam uses fake Google Forms site to harvest Google logins_MALWAREBYTES:1335B3D719E0A34DEC79C0CBFF0F266E - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=41329\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Job scam uses fake Google Forms site to harvest Google logins_MALWAREBYTES:1335B3D719E0A34DEC79C0CBFF0F266E - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2026-02-18T14:25:24&#8243;,&#8221;description&#8221;:&#8221;As part of our investigation into a job-themed phishing campaign, we came across several suspicious URLs that all looked like this:nn`https:\/\/forms.google.ss-o[.]com\/forms\/d\/e\/{unique_id}\/viewform?form=opportunitysecu0026promo=`nnThe subdomain `forms.google.ss-o[.]com` is a...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=41329\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2026-02-18T08:38:53+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=41329#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=41329\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"Job scam uses fake Google Forms site to harvest Google logins_MALWAREBYTES:1335B3D719E0A34DEC79C0CBFF0F266E\",\"datePublished\":\"2026-02-18T08:38:53+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=41329\"},\"wordCount\":750,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"exploit\",\"malwarebytes\",\"news\",\"NONE\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_news\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=41329#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=41329\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=41329\",\"name\":\"Job scam uses fake Google Forms site to harvest Google logins_MALWAREBYTES:1335B3D719E0A34DEC79C0CBFF0F266E - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2026-02-18T08:38:53+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=41329#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=41329\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=41329#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Job scam uses fake Google Forms site to harvest Google logins_MALWAREBYTES:1335B3D719E0A34DEC79C0CBFF0F266E\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Job scam uses fake Google Forms site to harvest Google logins_MALWAREBYTES:1335B3D719E0A34DEC79C0CBFF0F266E - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=41329","og_locale":"en_US","og_type":"article","og_title":"Job scam uses fake Google Forms site to harvest Google logins_MALWAREBYTES:1335B3D719E0A34DEC79C0CBFF0F266E - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2026-02-18T14:25:24&#8243;,&#8221;description&#8221;:&#8221;As part of our investigation into a job-themed phishing campaign, we came across several suspicious URLs that all looked like this:nn`https:\/\/forms.google.ss-o[.]com\/forms\/d\/e\/{unique_id}\/viewform?form=opportunitysecu0026promo=`nnThe subdomain `forms.google.ss-o[.]com` is a...","og_url":"https:\/\/zero.redgem.net\/?p=41329","og_site_name":"zero redgem","article_published_time":"2026-02-18T08:38:53+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=41329#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=41329"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"Job scam uses fake Google Forms site to harvest Google logins_MALWAREBYTES:1335B3D719E0A34DEC79C0CBFF0F266E","datePublished":"2026-02-18T08:38:53+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=41329"},"wordCount":750,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","exploit","malwarebytes","news","NONE","Security","tapic","Vulnerability"],"articleSection":["category_news"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=41329#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=41329","url":"https:\/\/zero.redgem.net\/?p=41329","name":"Job scam uses fake Google Forms site to harvest Google logins_MALWAREBYTES:1335B3D719E0A34DEC79C0CBFF0F266E - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2026-02-18T08:38:53+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=41329#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=41329"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=41329#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"Job scam uses fake Google Forms site to harvest Google logins_MALWAREBYTES:1335B3D719E0A34DEC79C0CBFF0F266E"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/41329","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=41329"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/41329\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=41329"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=41329"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=41329"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}