logo

Parsing Google Docs HTML

ID: 608dca87-46bc-5ee7-9c63-d85ecb00ade0

STIX ID: report--608dca87-46bc-5ee7-9c63-d85ecb00ade0

Feed Name: KMsec blog

Threat Score
45/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

...
...

This analysis demonstrates a method to extract document metadata, text, embedded links, and images from Google Docs HTML script tags, and applies it to a corpus of 25,000+ public docs to uncover a phishing campaign targeting financial brands (e.g., American Express) with observable malicious links; the author provides a parsing tool and searchable corpus to hunt related documents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.