Phish of the Week
August 24, 2026 · Last updated on August 21, 2026

Phish of the Week 24th of August

Phish of the Week 24th of August
# Phish of the Week
# Phishing

Google Ads on Air Impersonation

Mette Luntama
Mette Luntama
Phish of the Week 24th of August

Phish of the Week: Google Ads On Air Impersonation with AiTM Credential Harvester

This Phish of the Week breaks down a phishing campaign impersonating Ads On Air, a real Google Ads training program, to deliver employees straight into an adversary-in-the-middle (AiTM) credential harvester.

How the attack works:

The attack begins with an email that appears to come from an organization called BCAC, sent through the domain mail.workstream.is. Workstream is a legitimate third-party platform commonly used for HR and recruiting communications, so the email arrives through infrastructure that email security tools are less likely to flag as suspicious.
The email carries the real Google Ads logo and tells the recipient that their employer has invited them to participate in Ads On Air, described as an online session covering growth marketing, digital campaign planning, and other topics relevant to teams working in digital channels. It instructs the recipient to click the link to finalize their registration.
The email's footer includes a "Share this job with a friend" bar with social sharing icons, a leftover artifact from a recruitment email template that doesn't match the training-session narrative the email is telling.

Clicking the link takes the recipient to a landing page that closely mirrors the real Google Ads marketing site. The page is a near-exact visual copy of Google's own marketing page, reinforcing the impression that the recipient has reached a legitimate Google property.
After clicking the "View Your Invitation" button, the recipient is directed to a fake Google sign-in page designed to harvest their credentials. This page uses an adversary-in-the-middle (AiTM) technique, meaning the phishing infrastructure sits between the recipient and the real Google service, relaying whatever is entered in real time. This design is capable of capturing not just usernames and passwords but also session data, which can potentially allow attackers to bypass multi-factor authentication.


Why the attack works:

This attack's effectiveness comes primarily from what it doesn't do: it never pressures the recipient. There's no deadline, no warning about a missed opportunity, and no consequence threatened for inaction. Removing urgency also removes the psychological friction that often triggers suspicion, so recipients evaluate the email the way they would any other routine corporate notification, and routine notifications rarely get close scrutiny.
Each step also reinforces the one before it. The email arrives through Workstream's mail infrastructure rather than a spoofed sender, so its origin looks legitimate at the inbox level. The message body carries the real Google Ads logo and references Ads On Air, so the recipient isn't being asked to trust a fabricated scenario, only to believe that a real program applies to them. Clicking through lands on a near-identical copy of Google's own site, which confirms what the email already implied rather than introducing anything new to doubt.
The final credential harvester is also difficult to detect through casual inspection because it relies on AitM infrastructure rather than a simple static clone. Because it operates as a live relay to the real Google sign-in process, it can produce a login experience that behaves the way a genuine Google sign-in would, including handling multi-factor prompts, which removes one of the checks recipients might otherwise rely on to catch a fake page.

How to spot similar attacks:

  • The invitation refers to a training or event the recipient did not independently register for.
  • The sender's domain belongs to a third-party mailing platform rather than the recipient's employer or the brand being referenced.
  • The email footer contains elements, such as job-sharing icons, that don't match the stated purpose of the message.
  • The landing page URL shown in the browser bar does not match Google's official domain, even though the page visually resembles a Google property.
Rather than following a link in an unexpected training or event invitation, navigate directly to the official platform or contact your employer through a known channel to confirm the request.


What is Phish of the Week?

Phish of the Week is a weekly content initiative by Hoxhunt's Threat Operations team. Each week, we highlight a current phishing trend or notable real-world attack, covering what the threat is, how it works, and what to watch for to spot similar attacks in the future. The goal is to build consistent recognition of evolving phishing themes and tactics over time.
Comments (0)
Popular
avatar

Dive in

Related

Content
Phish of the Week 17th of August
By Mette Luntama • Aug 17th, 2026 Views 16
Content
Phish of the Week 27th of July
By Mette Luntama • Jul 27th, 2026 Views 13
Content
Phish of the Week 10th of August
By Mette Luntama • Aug 10th, 2026 Views 13
Content
Phish of the Week 03rd of August
By Mette Luntama • Aug 3rd, 2026 Views 8
Content
Phish of the Week 17th of August
By Mette Luntama • Aug 17th, 2026 Views 16
Content
Phish of the Week 10th of August
By Mette Luntama • Aug 10th, 2026 Views 13
Content
Phish of the Week 03rd of August
By Mette Luntama • Aug 3rd, 2026 Views 8
Content
Phish of the Week 27th of July
By Mette Luntama • Jul 27th, 2026 Views 13