A sophisticated phishing campaign has emerged, targeting organizations using Google Workspace , through deceptive emails impersonating Google's AppSheet platform

The attack demonstrates how cybercriminals are exploiting legitimate cloud services to bypass traditional email security measures and steal user credentials.
The campaign was discovered in September 2025 and represents a significant improvement in social engineering tactics, leveraging the innate trust that organizations place on Google's platform.
Abuse of Google AppSheet for phishing attacks
The malicious campaign exploits AppSheet’s widespread adoption by enterprises and its deep integration with Google Workspace infrastructure. By pretending to be legitimate AppSheet communications, the attackers are able to bypass email authentication protocolswhile delivering notifications trademark infringement to unsuspecting recipients. The effectiveness of the attack comes from abusing Google’s authentic infrastructure, making detection extremely difficult for conventional security systems.
See also: Chinese APT group develops EggStreme Fileless Malware
This phishing operation follows a pattern of abuse of legitimate services that security researchers have observed since March 2025, when similar campaigns exploited AppSheet to impersonate Meta and PayPal services. Raven identified the current campaign as an evolution of these previous tactics, noting that the attackers have refined their approach to maximize credential collection while maintaining operational security.
The most concerning aspect of the phishing campaign lies in its technical sophistication and authentication bypass capabilities. Unlike traditional phishing attacks that rely on compromised or spoofed domains, this operation leverages Google’s authentic email infrastructure to deliver malicious content. The messages originate from [noreply@appsheet.com], ensuring perfect SPF, DKIM, and DMARC authentication.

The attack exploits AppSheet's legitimate email functionality through multiple potential channels. Attackers either compromise existing user accounts on the platform or abuse the service's notification systems to create messages that appear to have been generated by Google's infrastructure.
Phishing emails contain professionally crafted content that mimics trademark enforcement notices, with urgent legal compliance requirements designed to provoke immediate action from users.
Critical to the campaign's success is the use of suspicious URL shorteners, particularly goo.su domains, which redirect victims to credential harvesting websites. These shortened links are embedded in otherwise legitimate legal notices, creating a convincing pretext for user interaction.
See also: Lazarus team exploits Git symlink vulnerability
Attackers strategically host phishing infrastructure on trusted platforms like Vercel, further enhancing the credibility and evasion capabilities of the enterprise. Detection proves difficult because the emails pass all traditional authentication checks while appearing contextually appropriate to recipients familiar with AppSheet’s usual communications.

This combination of technical legitimacy and sophisticated social engineering underscores the urgent need for email security solutions that analyze sender-content relationships rather than relying solely on authentication protocols. The campaign highlights how legitimate cloud services can become weapons of attack, forcing organizations to reexamine fundamental assumptions about trusted communications in enterprise environments.
See also: Critical vulnerability in Amp'ed RF BT-AP 111 Bluetooth Access Point
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The new phishing campaign using AppSheet reveals a disturbing pattern: cybercriminals don’t need to build fake infrastructure, but can camouflage themselves inside perfectly legitimate platforms. This means that classic defenses, such as SPF or DMARC, lose their effectiveness, leaving victims exposed. For businesses, the question is not whether an email looks “technically valid,” but whether the content matches real business activity. This development shows that protection cannot be based on filters and automation alone; it requires staff training, multi-layered monitoring, and investment in solutions that detect suspicious interactions beyond the obvious.
