A credential phishing campaign impersonates Google Ads MMC Sync maintenance notifications to trick users into synchronizing their accounts. The attack chain uses a spoofed sender domain, a blogspot redirect page, and a lookalike domain (mcc-sync-ads.com) hosting a Browser-in-the-Browser phishing page that simulates a legitimate Google sign-in popup to harvest credentials. The campaign leverages brand impersonation, false urgency, and multi-stage redirects to build trust and evade detection.
BitB phishing
1 post
Click to Sync: From Google Ads Maintenance Notice to Credential Theft