Also known as: tracked as, Aug 5, 2023, Coroxy, CVE-2025-40552, CVE-2025-40553, CVE-2026-2256, allows, fast16, evade security controls
GTFire is a threat actor that leverages Google Firebase for hosting phishing pages and Google Translate to disguise malicious URLs, effectively bypassing security filters. The campaign employs a multi-step redirect chain to obscure the final phishing destination and utilizes All-in-1 PHP phishing scripts for rapid deployment and credential harvesting. Credentials are exfiltrated via URL parameters in a standard HTTP GET request, with minimal operational overhead.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
GTFire is a threat actor leveraging Google Firebase and Google Translate to host phishing infrastructure, employing multi-stage redirect chains and All-in-1 PHP scripts for credential harvesting. The group’s low-observable tactics, including URL obfuscation and HTTP GET-based exfiltration, enable stealthy operations with minimal overhead. Organizations should prioritize monitoring for Firebase-hosted malicious domains and anomalous credential leaks.
Goals & Targeting
GTFire’s primary objectives appear to be unauthorized access to sensitive systems and the exfiltration of credentials, potentially for monetary gain or to facilitate further cyber intrusions. The actor’s use of Google Firebase and Google Translate suggests a focus on targeting sectors and regions where cloud adoption is high, such as technology, finance, and business services, particularly in areas with less stringent cybersecurity defenses. By leveraging legitimate platforms, the threat actor can bypass security measures that typically flag suspicious infrastructure, making it difficult for defenders to distinguish malicious activity from legitimate traffic. The lack of clear geopolitical motivations implies a profit-driven model, with victims likely being individuals or organizations that frequently interact with cloud-based services or handle sensitive user data such as credentials.
Enhanced Description
GTFire operates by utilizing Google Firebase, a trusted cloud service, to host phishing pages, which are then obfuscated using Google Translate to evade detection by security filters. This technique allows the actor to disguise malicious URLs as legitimate content, increasing the likelihood of user interaction. The campaign employs a multi-step redirect chain to further obscure the final phishing destination, making attribution and tracking significantly more challenging. Once users are lured into the phishing pages, the threat actor deploys All-in-1 PHP phishing scripts, which streamline the process of credential harvesting by automatically capturing and transmitting user data via URL parameters in HTTP GET requests. This method ensures operational efficiency while maintaining a low footprint. The absence of advanced persistence mechanisms or encryption in data exfiltration suggests a focus on speed and simplicity, likely targeting organizations with less sophisticated defensive postures. The use of cloud platforms for infrastructure hosting highlights the actor’s reliance on trusted services to bypass traditional security controls, indicating a deep understanding of modern web environments.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
GTFire’s campaigns follow a consistent pattern of exploiting trusted cloud services for infrastructure hosting, combined with URL obfuscation techniques to bypass security filters. The actor’s operational tempo suggests a focus on rapid deployment and minimal persistence, aligning with short-term financial motives rather than prolonged espionage. Campaigns often target individuals or organizations that rely heavily on cloud services for legitimate purposes, capitalizing on the inherent trust associated with such platforms. Notable past operations include the use of Firebase to host phishing pages that mimic legitimate websites, with no evidence of significant lateral movement or advanced persistence mechanisms.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in the described tactics and infrastructure based on the provided data. While the use of Google Firebase and Google Translate for obfuscation is well-documented, further intelligence on the actor’s motivations, operational scale, and potential ties to other campaigns would strengthen the assessment. The absence of direct attribution or samples for analysis introduces gaps in understanding the actor’s full capabilities and historical activities.
No campaigns linked yet.
No observed data linked yet.
2
Techniques
42
Tools
0
Campaigns
12
IOCs
0
Observed Data
2
Tactics