Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors GTFire

Also known as: tracked as, Aug 5, 2023, Coroxy, CVE-2025-40552, CVE-2025-40553, CVE-2026-2256, allows, fast16, evade security controls

Description

GTFire is a threat actor that leverages Google Firebase for hosting phishing pages and Google Translate to disguise malicious URLs, effectively bypassing security filters. The campaign employs a multi-step redirect chain to obscure the final phishing destination and utilizes All-in-1 PHP phishing scripts for rapid deployment and credential harvesting. Credentials are exfiltrated via URL parameters in a standard HTTP GET request, with minimal operational overhead.

Goals & Targeting

Targeted Sectors

Government
Financial services
Manufacturing
Mining
Information technology
Defense
Education

Targeted Countries / Regions

IN
SG
US
MX
ES
TW
AU
VN
JP
TR

AI Analysis

· 1 week ago

Executive Summary

GTFire is a threat actor leveraging Google Firebase and Google Translate to host phishing infrastructure, employing multi-stage redirect chains and All-in-1 PHP scripts for credential harvesting. The group’s low-observable tactics, including URL obfuscation and HTTP GET-based exfiltration, enable stealthy operations with minimal overhead. Organizations should prioritize monitoring for Firebase-hosted malicious domains and anomalous credential leaks.

Goals & Targeting

GTFire’s primary objectives appear to be unauthorized access to sensitive systems and the exfiltration of credentials, potentially for monetary gain or to facilitate further cyber intrusions. The actor’s use of Google Firebase and Google Translate suggests a focus on targeting sectors and regions where cloud adoption is high, such as technology, finance, and business services, particularly in areas with less stringent cybersecurity defenses. By leveraging legitimate platforms, the threat actor can bypass security measures that typically flag suspicious infrastructure, making it difficult for defenders to distinguish malicious activity from legitimate traffic. The lack of clear geopolitical motivations implies a profit-driven model, with victims likely being individuals or organizations that frequently interact with cloud-based services or handle sensitive user data such as credentials.

Enhanced Description

GTFire operates by utilizing Google Firebase, a trusted cloud service, to host phishing pages, which are then obfuscated using Google Translate to evade detection by security filters. This technique allows the actor to disguise malicious URLs as legitimate content, increasing the likelihood of user interaction. The campaign employs a multi-step redirect chain to further obscure the final phishing destination, making attribution and tracking significantly more challenging. Once users are lured into the phishing pages, the threat actor deploys All-in-1 PHP phishing scripts, which streamline the process of credential harvesting by automatically capturing and transmitting user data via URL parameters in HTTP GET requests. This method ensures operational efficiency while maintaining a low footprint. The absence of advanced persistence mechanisms or encryption in data exfiltration suggests a focus on speed and simplicity, likely targeting organizations with less sophisticated defensive postures. The use of cloud platforms for infrastructure hosting highlights the actor’s reliance on trusted services to bypass traditional security controls, indicating a deep understanding of modern web environments.

Key Capabilities

  • Leveraging Google Firebase for hosting phishing infrastructure
  • Obfuscating malicious URLs using Google Translate
  • Deploying multi-step redirect chains to evade detection
  • Utilizing All-in-1 PHP phishing scripts for rapid deployment
  • Exfiltrating credentials via HTTP GET requests in URL parameters
  • Minimal operational overhead through cloud-based hosting

MITRE ATT&CK Tactics

Initial Access
Execution
Credential Access
Exfiltration

ATT&CK Techniques

T1192 - Software Deployment
T1071.001 - Application Layer protocols (HTTP)
T1030 - Data Encoding
T1566.001 - Phishing
T1059.003 - HTTP

Software / Tooling

All-in-1 PHP phishing scripts
Google Firebase hosting
Google Translate API

Campaigns & Victims

GTFire’s campaigns follow a consistent pattern of exploiting trusted cloud services for infrastructure hosting, combined with URL obfuscation techniques to bypass security filters. The actor’s operational tempo suggests a focus on rapid deployment and minimal persistence, aligning with short-term financial motives rather than prolonged espionage. Campaigns often target individuals or organizations that rely heavily on cloud services for legitimate purposes, capitalizing on the inherent trust associated with such platforms. Notable past operations include the use of Firebase to host phishing pages that mimic legitimate websites, with no evidence of significant lateral movement or advanced persistence mechanisms.

IOC Patterns

  • Spear-phishing with malicious URLs obfuscated via Google Translate
  • Hosting of phishing pages on Google Firebase domains
  • C2 communication via HTTP GET requests using URL parameters
  • Multi-stage redirect chains to obscure phishing destinations
  • Deployment of All-in-1 PHP phishing scripts on compromised servers

Recommended Actions

  • Implement URL filtering and monitoring for obfuscated malicious domains hosted on Google Firebase
  • Deploy advanced phishing detection mechanisms to identify URLs using Google Translate for obfuscation
  • Monitor HTTP GET requests for anomalous credential exfiltration patterns in URL parameters
  • Regularly audit cloud infrastructure for unauthorized hosting of malicious content
  • Conduct employee training on recognizing phishing attempts with obfuscated URLs

Suggested Tags

Phishing
Credential Harvesting
Cloud-Based
APT
Spear-Phishing

Confidence Assessment

Moderate confidence in the described tactics and infrastructure based on the provided data. While the use of Google Firebase and Google Translate for obfuscation is well-documented, further intelligence on the actor’s motivations, operational scale, and potential ties to other campaigns would strengthen the assessment. The absence of direct attribution or samples for analysis introduces gaps in understanding the actor’s full capabilities and historical activities.

ATT&CK Techniques

Initial Access
1 technique
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.group-ib.com — Cited by web research for: evade security controls
  2. www.group-ib.com — Cited by web research for: Gentlemen
  3. malpedia.caad.fkie.fraunhofer.de — Cited by web research for: curl
  4. gbhackers.com — Cited by web research for: TeamViewer

Intel Summary

2

Techniques

42

Tools

0

Campaigns

12

IOCs

0

Observed Data

2

Tactics

Tags

Phishing
Credential Harvesting
Cloud-Based
APT
Spear-Phishing

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
United States (US)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.