{"id":12567,"date":"2026-05-02T10:03:41","date_gmt":"2026-05-02T10:03:41","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/05\/02\/attackers-abuse-google-appsheet-netlify-and-telegram-in-facebook-phishing-campaign\/"},"modified":"2026-05-02T10:03:41","modified_gmt":"2026-05-02T10:03:41","slug":"attackers-abuse-google-appsheet-netlify-and-telegram-in-facebook-phishing-campaign","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/05\/02\/attackers-abuse-google-appsheet-netlify-and-telegram-in-facebook-phishing-campaign\/","title":{"rendered":"Attackers Abuse Google AppSheet, Netlify, and Telegram in Facebook Phishing Campaign"},"content":{"rendered":"<p>    Attackers Abuse Google AppSheet, Netlify, and Telegram in Facebook Phishing Campaign<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated cybercriminal operation dubbed \u201cAccountDumpling\u201d has compromised approximately 30,000 Facebook accounts worldwide. <\/p>\n<p><a href=\"https:\/\/guard.io\/labs\/accountdumpling---hunting-down-the-google-sent-phishing-wave-compromising-30-000-facebook-accounts\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Discovered by Guardio Labs<\/a>, this Vietnamese-linked campaign abuses Google\u2019s AppSheet platform to bypass traditional email security filters. <\/p>\n<p>By routing fully authenticated phishing lures through legitimate channels, the attackers successfully harvest credentials and identity documents. These stolen <a href=\"https:\/\/cybersecuritynews.com\/hackers-hijack-facebook\/\" type=\"post\" id=\"47735\" target=\"_blank\" rel=\"noreferrer noopener\">Facebook Business accounts<\/a> are subsequently monetized or resold back to victims through an illicit storefront.<\/p>\n<p>The foundation of this campaign relies on hijacking platform trust rather than spoofing domains. The threat actors use Google AppSheet, a legitimate no-code app-building service, to distribute malicious notifications. <\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"766\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-4-1024x766.png?resize=1024%2C766&#038;ssl=1\" alt=\"Email phishing (Source: Guard Labs)\" class=\"wp-image-148950\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-4-1024x766.png 1024w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-4-300x224.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-4-768x574.png 768w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-4-1536x1149.png 1536w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-4-2048x1532.png 2048w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-4-562x420.png 562w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-4-80x60.png 80w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-4-150x112.png 150w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-4-696x521.png 696w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-4-1068x799.png 1068w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-4-1920x1436.png 1920w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-4-265x198.png 265w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\"><figcaption class=\"wp-element-caption\">Email phishing (Source: Guard Labs)<\/figcaption><\/figure>\n<p>Because these emails are sent directly from Google servers using the address\u00a0noreply@appsheet.com, they easily pass SPF, DKIM, and DMARC authentication checks. <\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"809\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-3-1024x809.png?resize=1024%2C809&#038;ssl=1\" alt=\"Account Dumpling (Source: Guard Labs)\" class=\"wp-image-148949\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-3-1024x809.png 1024w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-3-300x237.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-3-768x607.png 768w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-3-1536x1213.png 1536w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-3-2048x1618.png 2048w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-3-532x420.png 532w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-3-150x118.png 150w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-3-696x550.png 696w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-3-1068x844.png 1068w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-3-1920x1517.png 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\"><figcaption class=\"wp-element-caption\">Account Dumpling (Source: Guard Labs)<\/figcaption><\/figure>\n<p>Security defenders and <a href=\"https:\/\/cybersecuritynews.com\/best-spam-filter-tools\/\" type=\"post\" id=\"15518\" target=\"_blank\" rel=\"noreferrer noopener\">spam filters<\/a> consistently wave these messages through since Google genuinely owns the sending infrastructure. This forces victims to rely entirely on identifying the deceptive content within the message itself.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-attack-and-evasion-methodologies\"><strong>Attack and Evasion Methodologies<\/strong><\/h2>\n<p>The operation is highly modular, employing four distinct phishing clusters to target victims based on different psychological triggers.<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">Cluster Type<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Lure Strategy<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Hosting Platform<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Technical Features<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Policy Violation<\/td>\n<td>Fake Facebook Help Center notices threatening permanent account disablement\u00a0<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2026\/05\/30000-facebook-accounts-hacked-via.html\"><\/a>\n<\/td>\n<td>Netlify\u00a0<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2026\/05\/30000-facebook-accounts-hacked-via.html\"><\/a>\n<\/td>\n<td>HTTrack cloning artifacts, unique subdomains to evade blocklists, serverless functions for data exfiltration\u00a0<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/cyberinsider.com\/google-appsheet-abused-to-compromise-30000-facebook-accounts\/\"><\/a>\n<\/td>\n<\/tr>\n<tr>\n<td>Reward Promise<\/td>\n<td>Invitations for Blue Badge verification or exclusive advertiser rewards\u00a0<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2026\/05\/30000-facebook-accounts-hacked-via.html\"><\/a>\n<\/td>\n<td>Vercel\u00a0<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2026\/05\/30000-facebook-accounts-hacked-via.html\"><\/a>\n<\/td>\n<td>Unicode obfuscation in preheaders, fake reCAPTCHA barriers, live credential validation scripts\u00a0<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/cyberinsider.com\/google-appsheet-abused-to-compromise-30000-facebook-accounts\/\"><\/a>\n<\/td>\n<\/tr>\n<tr>\n<td>Live Control<\/td>\n<td>Urgent Meta notices disguised as a clean, single-image notification\u00a0<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/cyberinsider.com\/google-appsheet-abused-to-compromise-30000-facebook-accounts\/\"><\/a>\n<\/td>\n<td>Google Drive (Canva PDFs)\u00a0<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2026\/05\/30000-facebook-accounts-hacked-via.html\"><\/a>\n<\/td>\n<td>WebSocket-based live phishing panels enabling real-time, human-in-the-loop interaction\u00a0<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/cyberinsider.com\/google-appsheet-abused-to-compromise-30000-facebook-accounts\/\"><\/a>\n<\/td>\n<\/tr>\n<tr>\n<td>Social Engineering<\/td>\n<td>Fake senior job offers from prominent tech companies like Meta and Apple\u00a0<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2026\/05\/30000-facebook-accounts-hacked-via.html\"><\/a>\n<\/td>\n<td>Off-platform communication channels\u00a0<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/cyberinsider.com\/google-appsheet-abused-to-compromise-30000-facebook-accounts\/\"><\/a>\n<\/td>\n<td>Cyrillic homoglyphs in sender display names, pivoting to live conversations to slowly build trust\u00a0<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2026\/05\/30000-facebook-accounts-hacked-via.html\"><\/a>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>Behind the sophisticated front-end lures, the AccountDumpling operation relies entirely on Telegram bots for its command-and-control exfiltration. <\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"679\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-2-1024x679.png?resize=1024%2C679&#038;ssl=1\" alt=\"Telegram Phishing Campaign(Source: Guard Labs)\" class=\"wp-image-148948\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-2-1024x679.png 1024w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-2-300x199.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-2-768x509.png 768w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-2-1536x1018.png 1536w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-2-2048x1357.png 2048w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-2-634x420.png 634w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-2-150x99.png 150w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-2-696x461.png 696w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-2-1068x708.png 1068w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-2-1920x1273.png 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\"><figcaption class=\"wp-element-caption\">Telegram Phishing Campaign(Source: Guard Labs)<\/figcaption><\/figure>\n<p>Stolen credentials, two-factor authentication codes, dates of birth, and government-issued ID photos are instantly routed to private Telegram channels. <\/p>\n<p>Operators actively monitor these streams to <a href=\"https:\/\/cybersecuritynews.com\/hackerone-data-breach\/\" target=\"_blank\" rel=\"noreferrer noopener\">validate the stolen data <\/a>and execute account takeovers in real time. Telemetry from the recovered bot infrastructure indicates roughly 30,000 victim records have been processed. <\/p>\n<p>Geographic analysis reveals that 68.6 percent of the targeted individuals and businesses are located in the United States.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"592\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-1-1024x592.png?resize=1024%2C592&#038;ssl=1\" alt=\"Canva Generated Phishing (Source: Guard Labs)\" class=\"wp-image-148947\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-1-1024x592.png 1024w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-1-300x173.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-1-768x444.png 768w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-1-1536x887.png 1536w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-1-2048x1183.png 2048w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-1-727x420.png 727w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-1-150x87.png 150w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-1-696x402.png 696w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-1-1068x617.png 1068w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-1-1920x1109.png 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\"><figcaption class=\"wp-element-caption\">Canva Generated Phishing (Source: Guard Labs)<\/figcaption><\/figure>\n<p>Guardio Labs successfully traced the core of the operation to a Vietnamese threat actor through a critical operational security failure. <\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"674\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-1024x674.png?resize=1024%2C674&#038;ssl=1\" alt=\"Phishing Campaign (Source: guardLabs)\" class=\"wp-image-148946\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-1024x674.png 1024w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-300x197.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-768x505.png 768w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-1536x1011.png 1536w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-2048x1347.png 2048w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-638x420.png 638w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-150x99.png 150w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-696x458.png 696w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-1068x703.png 1068w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-1920x1263.png 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\"><figcaption class=\"wp-element-caption\">Phishing Campaign (Source: guardLabs)<\/figcaption><\/figure>\n<p>A Canva-generated PDF used in the third attack cluster retained its author metadata, exposing the real name \u201cPH\u1ea0M T\u00c0I T\u00c2N\u201d. Investigators connected this name to a public business persona in Vietnam that actively advertises Facebook account recovery and security services. <\/p>\n<p>This reveals a circular criminal economy in which attackers steal valuable business assets, use them to run fraudulent campaigns, and then attempt to sell recovery services back to the original victims.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/attackers-abuse-google-appsheet-netlify-and-telegram\/\">Attackers Abuse Google AppSheet, Netlify, and Telegram in Facebook Phishing Campaign<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Dhivya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/attackers-abuse-google-appsheet-netlify-and-telegram\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Attackers Abuse Google AppSheet, Netlify, and Telegram in Facebook Phishing Campaign A sophisticated cybercriminal operation dubbed \u201cAccountDumpling\u201d has compromised approximately 30,000 Facebook accounts worldwide. Discovered by Guardio Labs, this Vietnamese-linked campaign abuses Google\u2019s AppSheet platform to bypass traditional email security filters. By routing fully authenticated phishing lures through legitimate channels, the attackers successfully harvest credentials [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,163,124,1],"tags":[130],"class_list":["post-12567","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-google","category-phishing","category-uncategorized","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12567"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12567"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12567\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12567"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12567"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12567"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}