GTFire
- First seen
- 2022-05-15 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- intermediate
- Resource level
- individual
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:25:43
Targeted industries: financial-services technology-and-telecommunications professional-services retail-and-hospitality
Context
GTFire is a threat actor that leverages Google Firebase for hosting phishing pages and Google Translate to disguise malicious URLs, effectively bypassing security filters. The campaign employs a multi-step redirect chain to obscure the final phishing destination and utilizes All-in-1 PHP phishing scripts for rapid deployment and credential harvesting. Credentials are exfiltrated via URL parameters in a standard HTTP GET request, with minimal operational overhead.
Reports & references
- group-ib.com — Gtfire Phishing Scheme (report)