By: Elaine Irinco, Cofense Phishing Defense Center
Threat actors continue to exploit trusted brands and familiar workflows to draw users into phishing attacks. Scenarios that resemble routine account maintenance combine urgency with familiarity, increasing the likelihood that a recipient will act before verifying the request.
The Cofense Phishing Defense Center (PDC) observed a campaign targeting Google Ads Sync Accounts (MMC). The attackers sent fraudulent system-upgrade notices that instructed recipients to synchronize their accounts immediately. The lure used Google branding and the language of an operational requirement as a prerequisite for credential harvesting.
Platforms such as Google, Microsoft, and Amazon are embedded in daily business processes, which makes their brands useful starting points for malicious activity. Attackers depend on that recognition to gain attention and reduce skepticism.
Figure 1: Spoofed Google Ads MMC Sync Maintenance Notification
The sender display name suggested that the message came from Google Ads MMC Sync, but the actual sender domain—enavalenceart[.]com—was unrelated to Google. The email described a system upgrade and warned that accounts not synchronized within the specified window could experience service interruption or limitations. A “Complete Sync Account” button provided the next step.
The prominent Google branding reinforced legitimacy. Familiar visual elements can cause recipients to focus on the requested action instead of validating the sender and destination.
Figure 2: Spoofed Google Ads Redirection Page
After clicking, the recipient was redirected to a Blogspot page at hxxps://syncmcchub[.]blogspot[.]com/2026/06/syncmcchub[.]html. A Google Ads logo, loading indicator, and continue button briefly appeared during the redirect. This intermediate step made the journey feel more like a normal application workflow while concealing the transition to attacker-controlled infrastructure.
Figure 3: Google Ads Account Sync Phishing Page
The next page was hosted at hxxps://mcc-sync-ads[.]com/, a newly created lookalike domain that was not owned by Google. The domain name and page design were intended to resemble a legitimate Google Ads property closely enough to keep the user moving through the process.
Figure 4: Google login embedded within Google Ads Account Sync Phishing Page
Figure 4: Google sign-in form embedded in the Google Ads account-sync phishing page
The final page included a Google sign-in button. Clicking it displayed a JavaScript form designed to imitate the legitimate Google sign-in experience. The apparent pop-up accepted and stored the victim’s credentials while maintaining the visual continuity of a trusted brand.
The Attack Is a Trust-Building Sequence
Each stage of this campaign reduces friction for the victim: a familiar maintenance notice, recognizable branding, an intermediate loading page, a lookalike domain, and finally a simulated sign-in experience. Any one element may look only mildly suspicious. Together, they form a coordinated credential-theft workflow.
Attackers can reproduce this sequence across multiple senders, domains, subjects, and landing pages, which is why exact indicator matching may stop one variant without exposing the larger campaign.
User awareness and reporting remain critical, especially for unexpected account-maintenance requests. But modern phishing defense cannot depend on the recipient spotting every anomaly. Employee reports should feed a connected post-perimeter workflow that validates the threat, identifies related variants, and removes confirmed malicious messages from other inboxes.
Cofense combines phishing-specific AI trained on expert-validated, real-world intelligence with campaign-level remediation. Vision AI can cluster structurally related messages even when attackers rotate senders, subjects, URLs, and page elements. Once a threat is confirmed, analyst-controlled quarantine can extend across the related campaign, with explainable decisions and a full audit trail. Schedule a demo to see how Cofense helps stop trusted-brand credential phishing after it gets through.