Email attacks featuring Google Cloud Application Integration abuse and captcha.html · Blog · Sublime Security
ID: 68630b66-c3ee-58af-970e-ad3c554a544c
STIX ID: report--68630b66-c3ee-58af-970e-ad3c554a544c
Feed Name: Sublime Security Blog
Sublime’s Attack Spotlight details a credential-phishing campaign that leverages Google Cloud Application Integration to send authenticated-looking emails and hosts an LLM-generated, multi-challenge CAPTCHA on Google Cloud Storage to filter bots before redirecting victims to credential phishing pages; the report describes the attack flow, the CAPTCHA’s bot-detection and challenge configuration, observed indicators (storage.cloud.google.com links, suspicious URLs, Google impersonation, urgency), and Sublime’s detection signals and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
