{"id":4333,"date":"2025-05-31T10:00:15","date_gmt":"2025-05-31T10:00:15","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/05\/31\/threat-actors-leverage-google-apps-script-to-host-phishing-websites\/"},"modified":"2025-05-31T10:00:15","modified_gmt":"2025-05-31T10:00:15","slug":"threat-actors-leverage-google-apps-script-to-host-phishing-websites","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/05\/31\/threat-actors-leverage-google-apps-script-to-host-phishing-websites\/","title":{"rendered":"Threat Actors Leverage Google Apps Script To Host Phishing Websites"},"content":{"rendered":"<p>    Threat Actors Leverage Google Apps Script To Host Phishing Websites<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Cybercriminals have escalated their tactics by exploiting Google Apps Script, a trusted development platform, to host sophisticated phishing campaigns that bypass traditional security measures.<\/p>\n<p>This emerging threat represents a significant shift in how attackers leverage legitimate infrastructure to enhance the credibility of their <a href=\"https:\/\/cybersecuritynews.com\/silver-rat-malware-with-new-anti-virus-bypass-techniques\/\" target=\"_blank\" rel=\"noreferrer noopener\">malicious operations<\/a>.<\/p>\n<p>The latest campaign targets unsuspecting users through deceptive invoice emails that appear to originate from legitimate disability and health equipment providers.<\/p>\n<p>These carefully crafted messages contain minimal content to avoid triggering spam filters while creating urgency that prompts immediate action from recipients.<\/p>\n<p>The attackers deliberately exploit the inherent trust users place in communications that appear business-related and time-sensitive.<\/p>\n<p>Cofense analysts <a href=\"https:\/\/cofense.com\/blog\/behind-the-script-unmasking-phishing-attacks-using-google-apps-script\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> this sophisticated phishing operation through their Phishing Defense Center, revealing how threat actors have weaponized Google\u2019s own infrastructure to create an illusion of authenticity.<\/p>\n<p>By hosting malicious content on script.google.com domains, attackers effectively circumvent many security solutions that typically whitelist <a href=\"https:\/\/cybersecuritynews.com\/hackers-abuse-google-services\/\" target=\"_blank\" rel=\"noreferrer noopener\">Google services<\/a>, making detection significantly more challenging for both automated systems and end users.<\/p>\n<p>The campaign\u2019s impact extends beyond simple credential theft, as successful attacks provide cybercriminals with access to corporate email systems and sensitive organizational data.<\/p>\n<p>The use of Google\u2019s trusted environment dramatically increases the likelihood of successful compromise, as users are conditioned to trust Google-hosted content without scrutiny.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Multi-Stage Infection Mechanism<\/strong><\/h2>\n<p>The attack unfolds through a carefully orchestrated sequence designed to maximize victim engagement while minimizing suspicion.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj2OyDbwKKn477WuYffylVKyCfUHNsFhtNxMaXfCwt3tCrXMGHpk4YBZEvRBzKWpGX6KUGZiBrGD2r82U79s2R0GYKHt6MTmJZvyk36j4rQCk8oTtefOG052o_lDAev-YcGW-ylzyMBwx-2NC4FzSdS0BeMRFK0ORCQQ-yJWIj0kJ9DLOE1VzIf94HQdU4\/s16000\/Email%2520Body%2520%28Source%2520-Cofense%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Email Body (Source -Cofense)<\/figcaption><\/figure>\n<\/div>\n<p>Initial infection begins when recipients click the \u201cView Invoice\u201d link in the spoofed email, which redirects them to a <a href=\"https:\/\/cybersecuritynews.com\/google-to-block-malicious-sideloaded-apps\/\" target=\"_blank\" rel=\"noreferrer noopener\">Google Apps<\/a> Script-hosted page displaying what appears to be a legitimate electronic fax download interface.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhsEfSPHiYR3zq-tE_1SCM7kCAWBA1fhtFMDNnS9AviWn-AI45Cvf59glkz_7VIUtn2dXuADldlf4xnhwbTYnwbTjnU4goPpsvin5-v4LR-nSrPD6vPSlI_Bs8PJ0e3NbMnmQGE8dZkAiRjT9TsIw5GtQrrJDC6aHeKmC-jBPKpy2OoWyQGap6iH5M9ddw\/s16000\/Fake%2520Invoice%2520Page%2520%28Source%2520-Cofense%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Fake Invoice Page (Source -Cofense)<\/figcaption><\/figure>\n<\/div>\n<p>The critical transition occurs when users click the \u201cPreview\u201d button, triggering the deployment of a fraudulent login window that mimics authentic <a href=\"https:\/\/cybersecuritynews.com\/microsoft-dataverse-authentication-flaw\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft authentication<\/a> interfaces.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj8GJc-ssEh6RTqLSiPgEnAnjdUHb5H6hJbYnGzI_Zn_SGj_02OgmYhoulPvWdywsDW5PagkLsdzzDy_6gZfuXohi8lJUJVVgkIcbHy27_3eJgip-qiHL4AXsEuMkqPZk8Ygap1NWS4LwxxMiAf4NoQOAJfi71ykNUojoCDkYgR9MIBWJ6c8JIFW0RGCco\/s16000\/Phishing%2520Page%2520%28Source%2520-Cofense%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Phishing Page (Source -Cofense)<\/figcaption><\/figure>\n<p>Once credentials are entered, a PHP script immediately captures and transmits the data to attacker-controlled servers before seamlessly redirecting victims to a legitimate <a href=\"https:\/\/cybersecuritynews.com\/flowerstorm-phishing-as-a-service\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft login page<\/a> to maintain the deception.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjKgV2TFnaE8hc_V3F_-SaUuD6ejioh1DQ2wQeLuDkp14zHCwvxBNA9NlI12QUeiAX_H_Sq6oZfD_ZTgLQSmdhckYeJTizaiMPfJws3_PflBqmaeqea1MlPz7JHKjRunHy5RSdxodZzP-T6a1xET3KWfAqzDIo6IHHCK2joFfUhNwyX9Xi0lFdUzHiSMW4\/s16000\/Final%2520redirect%2520page%2520%28Source%2520-Cofense%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Final redirect page (Source -Cofense)<\/figcaption><\/figure>\n<\/div>\n<p>This final redirection serves as psychological camouflage, leaving victims unaware that their credentials have been compromised while providing attackers with immediate access to corporate systems and sensitive information.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 89%,rgb(169,184,195) 100%)\"><strong>Celebrate 9 years of ANY.RUN!\u00a0<strong>Unlock the full power of<\/strong>\u00a0TI Lookup plan (100\/300\/600\/1,000+ search requests),\u00a0and\u00a0<a href=\"https:\/\/intelligence.any.run\/plans?utm_source=linkedin_csn&amp;utm_medium=post&amp;utm_campaign=spring_offer&amp;utm_content=plans&amp;utm_term=290525\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">your request quota will double<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/threat-actors-leverage-google-apps-script\/\">Threat Actors Leverage Google Apps Script To Host Phishing Websites<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/threat-actors-leverage-google-apps-script\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Threat Actors Leverage Google Apps Script To Host Phishing Websites Cybercriminals have escalated their tactics by exploiting Google Apps Script, a trusted development platform, to host sophisticated phishing campaigns that bypass traditional security measures. This emerging threat represents a significant shift in how attackers leverage legitimate infrastructure to enhance the credibility of their malicious operations. [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-4333","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4333"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=4333"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4333\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=4333"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=4333"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=4333"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}