Skip to main content
Credential Theft in Four ClicksFraud Typologies
5 min readFor Fintech Risk and Compliance Teams

Credential Theft in Four Clicks

The Challenge

A phishing campaign targeting Google Ads Sync Accounts bypassed perimeter defenses. The attack used a spoofed Google Ads MMC Sync Maintenance Notification, warning recipients that accounts not synchronized within a specified window could face service interruption. The sender's display name read "Google Ads MMC Sync," but the actual sender domain was enavalenceart[.]com, unrelated to Google.

The real challenge wasn't detecting a single malicious email. It was recognizing that this message was the first step in a multi-stage credential-theft workflow, designed to mimic routine account maintenance. Each step reduced friction: a redirect to a Blogspot page at hxxps://syncmcchub[.]blogspot[.]com/2026/06/syncmcchub[.]html, a transition to the lookalike domain hxxps://mcc-sync-ads[.]com/, and finally a JavaScript form imitating Google's sign-in experience.

Organizations relying on indicator-based detection found themselves in a familiar position. They could block the specific sender domain or URL, but attackers had already shown they could rotate infrastructure. Blocking one variant wouldn't reveal the campaign structure.

The Environment and Constraints

The Cofense Phishing Defense Center analyzed this campaign in an environment where Google, Microsoft, and Amazon are integral to daily business processes. Brand recognition becomes a liability when attackers exploit it systematically.

Traditional email security relies on signature matching and reputation scoring. A message from enavalenceart[.]com might raise suspicion, but the domain had no prior malicious history at the time of sending. The Blogspot redirect used Google's own infrastructure. The final phishing page sat on a newly created domain with no established reputation.

User awareness training advises recipients to verify sender addresses and hover over links before clicking. But this attack sequence was designed to withstand scrutiny at each step. The maintenance notice looked plausible. The Blogspot redirect included a Google Ads logo and loading indicator, reinforcing the appearance of a legitimate workflow. The lookalike domain mcc-sync-ads[.]com contained recognizable keywords. The JavaScript sign-in form replicated Google's visual design.

Detection required connecting these elements into a campaign-level pattern, not evaluating each piece in isolation.

The Approach Taken

Cofense deployed Vision AI to cluster structurally related messages even when attackers rotated senders, subjects, URLs, and page elements. The system identified similarities in the attack sequence: the maintenance-notice framing, the intermediate redirect pattern, the lookalike domain structure, and the embedded credential-capture mechanism.

This approach shifted focus from blocking specific indicators to understanding campaign architecture. Vision AI recognized that messages sharing these structural elements belonged to the same threat, regardless of which sender domain or subject line variation the attackers used.

Once a threat was confirmed through analyst validation, Cofense's remediation workflow extended across the related campaign. The system quarantined messages matching the campaign pattern from other inboxes, with explainable decisions and a full audit trail.

The process relied on employee reports as initial intelligence. When a recipient flagged the Google Ads maintenance notice as suspicious, that report fed into a post-perimeter workflow that validated the threat, identified structural variants, and removed confirmed malicious messages before other users could interact with them.

Results and Metrics

The campaign demonstrated why exact indicator matching fails against adaptive attackers. Each stage used different infrastructure: enavalenceart[.]com for the initial sender, syncmcchub[.]blogspot[.]com for the redirect, and mcc-sync-ads[.]com for the final credential capture. Blocking any single element wouldn't prevent the next variant.

Vision AI's clustering capability meant that identifying one message in the sequence exposed the broader campaign structure. Remediation extended beyond the specific indicators to messages sharing the same attack pattern, even when senders and URLs differed.

The audit trail preserved analyst decisions at each step. When a message was quarantined based on campaign similarity, the system documented which structural elements triggered the match and which analyst confirmed the threat. This explainability matters for compliance frameworks that require documented decision-making processes.

What They Would Do Differently

The campaign revealed gaps in how organizations evaluate phishing risk. Many security teams still treat each suspicious email as an isolated incident, asking "Is this specific message malicious?" rather than "What campaign does this message belong to?"

A more effective approach starts with the assumption that any successful phishing message represents one variant in a larger campaign. When a user reports a Google Ads maintenance notice, the response shouldn't stop at blocking that sender domain. The question becomes: What other messages in our environment share this attack structure?

Organizations should also reconsider how they measure detection success. Blocking 100 malicious emails sounds effective until you realize they're all part of a 500-message campaign that rotated through five sender domains. Campaign-level detection metrics reveal whether your defenses are keeping pace with attacker infrastructure rotation.

Takeaways for Your Team

Build post-perimeter workflows that connect employee reports to campaign-level remediation. A single phishing report should trigger analysis of structurally similar messages across your environment, not just the reported message.

Evaluate detection systems based on their ability to identify campaign patterns, not just individual indicators. Attackers rotate infrastructure faster than you can update blocklists. Your defenses need to recognize the attack sequence, not memorize specific domains.

Implement Multi-Factor Authentication on all accounts that handle credentials or financial data. MFA doesn't prevent phishing, but it limits the damage when credentials are stolen. The Google Ads campaign captured usernames and passwords; it couldn't capture authenticator codes.

Require analyst validation before automated remediation at scale. AI-driven clustering can identify campaign patterns, but human judgment should confirm the threat before quarantining messages from hundreds of inboxes. Document those decisions for audit purposes.

Train users to report unexpected maintenance notices, even from familiar brands. The Google Ads campaign succeeded because it looked like routine account administration. Your reporting culture should encourage skepticism about urgent account-sync requests, regardless of branding.

The shift from indicator-based to behavior-based detection isn't optional anymore. Attackers have demonstrated they can rotate infrastructure faster than traditional defenses can adapt. Your response needs to match the campaign structure they're using, not the individual message they sent.

You Might Also Like