{"id":7191,"date":"2025-09-25T10:03:33","date_gmt":"2025-09-25T10:03:33","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/09\/25\/new-domain-fronting-attack-uses-google-meet-youtube-chrome-and-gcp-to-tunnel-traffic\/"},"modified":"2025-09-25T10:03:33","modified_gmt":"2025-09-25T10:03:33","slug":"new-domain-fronting-attack-uses-google-meet-youtube-chrome-and-gcp-to-tunnel-traffic","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/09\/25\/new-domain-fronting-attack-uses-google-meet-youtube-chrome-and-gcp-to-tunnel-traffic\/","title":{"rendered":"New Domain-fronting Attack Uses Google Meet, YouTube, Chrome and GCP to Tunnel Traffic"},"content":{"rendered":"<p>    New Domain-fronting Attack Uses Google Meet, YouTube, Chrome and GCP to Tunnel Traffic<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Organizations commonly allow traffic to core services like <a href=\"https:\/\/cybersecuritynews.com\/google-meet-encrypted-calls\/\" target=\"_blank\" rel=\"noreferrer noopener\">Google Meet<\/a>, YouTube, Chrome update servers, and Google Cloud Platform (GCP) to ensure uninterrupted operations.\u00a0<\/p>\n<p>A newly demonstrated domain fronting technique weaponizes this trust to establish covert <a href=\"https:\/\/cybersecuritynews.com\/command-and-controlc2-server\/\" target=\"_blank\" rel=\"noreferrer noopener\">command-and-control (C2) <\/a>channels, enabling attackers to tunnel malicious traffic through Google\u2019s own infrastructure without raising suspicion.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-domain-fronting-technique\"><strong>Domain Fronting Technique<\/strong><\/h2>\n<p>Praetorian reports that domain fronting exploits the discrepancy between the TLS Server Name Indication (SNI) and the HTTP Host header. In a standard HTTPS handshake, the client presents the SNI in cleartext, for example:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"400\" height=\"42\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-153.png?resize=400%2C42&#038;ssl=1\" alt=\"New Domain Fronting Attack\" class=\"wp-image-127946\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-153.png 400w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-153-300x32.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-153-150x16.png 150w\" sizes=\"auto, (max-width: 400px) 100vw, 400px\"><\/figure>\n<\/div>\n<p>Once the TLS tunnel is established, the HTTP Host header inside the encrypted request can specify an entirely different domain:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"360\" height=\"63\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-152.png?resize=360%2C63&#038;ssl=1\" alt=\"New Domain Fronting Attack\" class=\"wp-image-127940\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-152.png 360w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-152-300x53.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-152-356x63.png 356w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-152-150x26.png 150w\" sizes=\"auto, (max-width: 360px) 100vw, 360px\"><\/figure>\n<\/div>\n<p>By routing through Google\u2019s front-end servers, adversaries can connect to meet.google.com, youtube.com, update.googleapis.com, or even GCP endpoints, while backend routing diverts traffic to attacker-controlled infrastructure hosted on Google Cloud Run or App Engine.\u00a0<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"885\" height=\"221\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-151.png?resize=885%2C221&#038;ssl=1\" alt=\"Google.com Domain Fronting\" class=\"wp-image-127939\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-151.png 885w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-151-300x75.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-151-768x192.png 768w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-151-696x174.png 696w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-151-150x37.png 150w\" sizes=\"auto, (max-width: 885px) 100vw, 885px\"><figcaption class=\"wp-element-caption\">Google[.]com Domain Fronting<\/figcaption><\/figure>\n<\/div>\n<p>To network monitors, the packets appear indistinguishable from legitimate Google usage, blending malicious C2 with normal enterprise traffic.<\/p>\n<p>Researchers <a href=\"https:\/\/www.praetorian.com\/blog\/domain-fronting-is-dead-long-live-domain-fronting\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">created<\/a> a simple Cloud Run function returning \u201cHello World!\u201d and inserted its URL in the Host header when connecting to google.com.\u00a0<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"889\" height=\"561\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-150.png?resize=889%2C561&#038;ssl=1\" alt=\"Domain Fronting Across Google Services\" class=\"wp-image-127938\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-150.png 889w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-150-300x189.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-150-768x485.png 768w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-150-666x420.png 666w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-150-696x439.png 696w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-150-150x95.png 150w\" sizes=\"auto, (max-width: 889px) 100vw, 889px\"><figcaption class=\"wp-element-caption\">Domain Fronting Across Google Services<\/figcaption><\/figure>\n<\/div>\n<p>Unexpectedly, the Cloud Run function was invoked, confirming that the request had been routed to attacker infrastructure rather than Google\u2019s public web servers. This edge-case behavior extends across multiple <a href=\"https:\/\/cybersecuritynews.com\/hackers-exploiting-trusted-google-domains\/\" target=\"_blank\" rel=\"noreferrer noopener\">Google domains<\/a>, including:<\/p>\n<ul class=\"wp-block-list\">\n<li>update.googleapis.com<\/li>\n<li>payments.google.com<\/li>\n<li>api.snapchat.com (leveraging Google App Engine)<\/li>\n<\/ul>\n<p>Because these domains are often excluded from TLS inspection due to <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-for-penetration-testing\/\" target=\"_blank\" rel=\"noreferrer noopener\">certificate pinning<\/a> or classification as financial or healthcare services, security appliances rarely inspect or block them, granting attackers near-total invisibility.<\/p>\n<p>Historically, major providers blocked domain fronting by enforcing SNI and Host header consistency.\u00a0<\/p>\n<p>However, Google\u2019s internal load-balancer routing logic still allows mismatches in specific services, creating an unintentional fronting vector. The attack sequence is as follows:<\/p>\n<p>Initiate a TLS handshake with SNI set to a high-reputation Google domain (e.g., youtube.com). Within the encrypted request, set the Host header to the <a href=\"https:\/\/cybersecuritynews.com\/command-and-controlc2-server\/\" target=\"_blank\" rel=\"noreferrer noopener\">C2 domain<\/a> hosted on Cloud Run or App Engine.<\/p>\n<p>Google\u2019s front-end accepts the SNI, terminates TLS, and routes the decrypted HTTP request to backend infrastructure based on the Host header. The attacker\u2019s backend handles the request, enabling bidirectional tunneling through standard HTTPS.<\/p>\n<p>A redirector tool, praetorian-inc\/google-redirector, automates setup for red team engagements. Deploying this redirector alongside existing implants allows seamless HTTP-based C2 over Google\u2019s highly trusted channels.<\/p>\n<p>This technique revives the power of domain fronting within Google\u2019s ecosystem, presenting defenders with a formidable challenge: blocking malicious C2 without disrupting essential business services.\u00a0<\/p>\n<p>Vigilance demands enhanced detection strategies, such as certificate consistency checks, analysis of abnormal traffic patterns, and strict host validation at the enterprise perimeter.\u00a0<\/p>\n<p>As attackers turn the Internet\u2019s backbone into their covert pipeline, defenders must adapt to identify hidden threats that are hiding in plain sight.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/domain-fronting-attack\/\">New Domain-fronting Attack Uses Google Meet, YouTube, Chrome and GCP to Tunnel Traffic<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Florence Nightingale<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/domain-fronting-attack\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New Domain-fronting Attack Uses Google Meet, YouTube, Chrome and GCP to Tunnel Traffic Organizations commonly allow traffic to core services like Google Meet, YouTube, Chrome update servers, and Google Cloud Platform (GCP) to ensure uninterrupted operations.\u00a0 A newly demonstrated domain fronting technique weaponizes this trust to establish covert command-and-control (C2) channels, enabling attackers to tunnel [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1636,129,63],"tags":[130],"class_list":["post-7191","post","type-post","status-publish","format-standard","hentry","category-cyber-attack-news","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7191"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7191"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7191\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7191"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7191"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7191"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}