Hackers use Google Analytics, checking attack success rates: Phishing has evolved over time and continues to successfully convince victims to reveal sensitive or confidential data.
Recently, researchers have observed that black-hat hackers are using legitimate web analytics tools to track the metrics of phishing campaigns.

Utilizing websites for data analysis
Website Analytics is a great tool for tracking performance (ROI), including user behavior, page navigation, and technical metrics. Hackers also use these tools to track metrics for phishing campaigns.
Details such as browsers, countries, and operating systems are collected through website analytics to modify the phishing campaign for higher success rates.
The researchers examined 62,627 active phishing addresses belonging to thousands of unique domains. Unique identifiers on many domains were observed to be linked to Google Analytics .
While some malicious domains had Google Analytics IDs, possibly for tracking metrics, some ID codes appear to have been stolen from original domains and reused.

Security experts have discovered a phishing campaign targeting LinkedIn users from April to July of this year. It used an analytics network ID associated with several phishing domains targeting LinkedIn.
"The campaign registered several deceptive domains to lure its victims, but each domain hosted a different variation of the phishing kit's source code, making them difficult to detect without the Google ID," the researchers said.
Using the same analytics tools for defense
tracking ID can be useful for researchers and security experts to dismantle campaigns by shutting down fake websites.
A campaign targeting AirBnB logins created malicious subdomains to avoid detection. But all of these subdomains used the same UID, which helped researchers detect and shut down the campaign.
