Attackers route phishing victims through Google's DoubleClick domain to evade detection before deploying the DesckVB RAT trojan.