HomeSecurityPhishing: Hackers abuse Google Apps Script

Phishing: Hackers abuse Google Apps Script

Security researchers at Cofense have identified a new tactic phishingin which cybercriminals are leveraging Google Apps Script, Google's cloud development platform, to host fake login pages that mimic legitimate interfaces. Their goal is to steal user credentials.

Google Apps Script phishing

According to the researchers, the attacks typically begin with deceptive emails that appear to be invoices and contain links to websites created using the Google Apps Script platform. These websites are hosted within Google's environment, giving attackers the illusion of trust. As a result, users are more easily tricked into handing over their credentials.

"The fake login form is carefully designed to look like a genuine login page," Cofense warns.

See also: FBI: Warns of phishing attacks by Silent Ransom Group

Abuse of legal services: The new trend

Google Apps Script is a JavaScript-based tool that allows you to automate tasks and extend functionality in products like Google Sheets, Docs, Drive, Gmail, and Calendar. However, the ability to run scripts within the trusted domain, script.google.com, offers a loophole for cybercriminals to exploit.

Attackers create a Google Apps Script that displays a fake login page, extracting sensitive information from unsuspecting victims. The entered data is silently sent to the attackers' remote servers via background HTTP requests.

As the platform allows anyone (with an account) to publish a script as a public web app, giving it a Google domain, threat actors can easily share it with victims via a phishing email that will not trigger any warnings.

As we mentioned earlier, the scam begins by sending deceptive emails—often with titles like “Pay Bill” or “Important Tax Information”—which redirect the recipient to phishing pages hosted directly on Google’s environment.

Once the user enters their credentials, they are automatically redirected to the legitimate service page. This way, criminals reduce the victim's suspicion and buy time to exploit the stolen data.

Google Apps Script as a "multi-purpose tool" for phishing

The trend shows that Google Apps Script has become a hotbed of phishing attacks, as it offers attackers the ability to modify the script remotely, without having to send a different link. This allows them to refresh the bait or change strategy with minimal effort.

See also: Phishing emails distribute Horabot malware in Latin America

The abuse of this platform raises serious questions about the security of cloud services and the need to restrict or monitor URLs associated with Google scripts.

Recommended protection measures

Experts recommend strengthening email security filters to identify and control links that lead to cloud service links. In high-risk environments, it is even advisable to URLs script.google.com or at least mark them as potentially dangerous.

General tips for protection against phishing

Phishing attacks can be very effective, but you can protect yourself by following these basic tips:

Be wary of suspicious emails and messages

  • Do not click on links or download attachments from unknown or unexpected senders.
  • Check carefully email address —phishers often use similar-looking addresses.
  • Look for spelling and grammatical errors, which are common in phishing emails.

Verify before you act

  • If an email requires immediate action (like “Your account will be locked!”), verify directly by visiting the official website instead of clicking on links.
  • Contact the sender through official channels (if you are unsure).

Hover over links (before clicking)

  • Hover over links to see the actual URL before clicking. If it looks strange or different from the official domain, don't click.

Enable multi-factor authentication (MFA)

  • Even if a hacker gets password , MFA adds an extra layer of security (like a code sent to your phone).

See also: New phishing attack abuses Blob URIs to bypass SEG

Phishing: Hackers abuse Google Apps Script
Phishing: Hackers abuse Google Apps Script

Keep software and security tools up to date

  • Regularly update your browser, operating system, and antivirus software to protect against malware.

See also: Darcula phishing: Thousands of credit cards stolen

Don't share sensitive information via email

  • Legitimate companies will not ask for passwords, social security numbers, or banking information via email.

Educate yourself and your team

  • Stay up to date on the latest phishing tactics and train employees or family members on how to spot them.

Use a Password Manager

  • Password managers help create and store strong, unique passwords for each website, reducing the risk of a breach.

Report Phishing Attempts

  • If you receive a phishing message, report it to your email provider and the company being impersonated.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS