HomeSecurityNew phishing attack mimics Google AppSheet

New phishing attack mimics Google AppSheet

A sophisticated phishing campaign has emerged, targeting organizations using Google Workspace , through deceptive emails impersonating Google's AppSheet platform

Google AppSheet phishing

The attack demonstrates how cybercriminals are exploiting legitimate cloud services to bypass traditional email security measures and steal user credentials.

The campaign was discovered in September 2025 and represents a significant improvement in social engineering tactics, leveraging the innate trust that organizations place on Google's platform.

Abuse of Google AppSheet for phishing attacks

The malicious campaign exploits AppSheet’s widespread adoption by enterprises and its deep integration with Google Workspace infrastructure. By pretending to be legitimate AppSheet communications, the attackers are able to bypass email authentication protocolswhile delivering notifications trademark infringement to unsuspecting recipients. The effectiveness of the attack comes from abusing Google’s authentic infrastructure, making detection extremely difficult for conventional security systems.

See also: Chinese APT group develops EggStreme Fileless Malware

This phishing operation follows a pattern of abuse of legitimate services that security researchers have observed since March 2025, when similar campaigns exploited AppSheet to impersonate Meta and PayPal services. Raven identified the current campaign as an evolution of these previous tactics, noting that the attackers have refined their approach to maximize credential collection while maintaining operational security.

The most concerning aspect of the phishing campaign lies in its technical sophistication and authentication bypass capabilities. Unlike traditional phishing attacks that rely on compromised or spoofed domains, this operation leverages Google’s authentic email infrastructure to deliver malicious content. The messages originate from [noreply@appsheet.com], ensuring perfect SPF, DKIM, and DMARC authentication.

New phishing attack mimics Google AppSheet

The attack exploits AppSheet's legitimate email functionality through multiple potential channels. Attackers either compromise existing user accounts on the platform or abuse the service's notification systems to create messages that appear to have been generated by Google's infrastructure.

Phishing emails contain professionally crafted content that mimics trademark enforcement notices, with urgent legal compliance requirements designed to provoke immediate action from users.

Critical to the campaign's success is the use of suspicious URL shorteners, particularly goo.su domains, which redirect victims to credential harvesting websites. These shortened links are embedded in otherwise legitimate legal notices, creating a convincing pretext for user interaction.

See also: Lazarus team exploits Git symlink vulnerability

Attackers strategically host phishing infrastructure on trusted platforms like Vercel, further enhancing the credibility and evasion capabilities of the enterprise. Detection proves difficult because the emails pass all traditional authentication checks while appearing contextually appropriate to recipients familiar with AppSheet’s usual communications.

New phishing attack mimics Google AppSheet

This combination of technical legitimacy and sophisticated social engineering underscores the urgent need for email security solutions that analyze sender-content relationships rather than relying solely on authentication protocols. The campaign highlights how legitimate cloud services can become weapons of attack, forcing organizations to reexamine fundamental assumptions about trusted communications in enterprise environments.

See also: Critical vulnerability in Amp'ed RF BT-AP 111 Bluetooth Access Point

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The new phishing campaign using AppSheet reveals a disturbing pattern: cybercriminals don’t need to build fake infrastructure, but can camouflage themselves inside perfectly legitimate platforms. This means that classic defenses, such as SPF or DMARC, lose their effectiveness, leaving victims exposed. For businesses, the question is not whether an email looks “technically valid,” but whether the content matches real business activity. This development shows that protection cannot be based on filters and automation alone; it requires staff training, multi-layered monitoring, and investment in solutions that detect suspicious interactions beyond the obvious.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS