logo

Phantoms in the Cloud: Fraudsters Exploit Google Cloud Storage for Deceptive Campaigns

ID: 9145c161-203d-52c0-a401-c99c6673973b

STIX ID: report--9145c161-203d-52c0-a401-c99c6673973b

Feed Name: Aryaka

Threat Score
65/100

Date Published: 2025-12-04

Date Updated: 2026-04-27

Author: Aditya K Sood

...
...

Aryaka Threat Research Labs discovered a financially motivated cloud-based phishing campaign that leverages Google Cloud Storage to host HTML redirectors and fraudulent prize/bonus sites. Attackers impersonate trusted services (e.g., Gmail, Google Drive), exploit gaps in email authentication (SPF pass with missing DKIM and weak DMARC), use CAPTCHA challenges to evade automated analysis, and collect user/browser data via analytics platforms to refine targeting; Aryaka disclosed the abuse to Google Cloud and coordinated with Proofpoint to update detection rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.