logo

Email attacks featuring Google Cloud Application Integration abuse and captcha.html · Blog · Sublime Security

ID: 68630b66-c3ee-58af-970e-ad3c554a544c

STIX ID: report--68630b66-c3ee-58af-970e-ad3c554a544c

Feed Name: Sublime Security Blog

Threat Score
65/100

Date Published: 2026-01-29

Date Updated: 2026-05-01

...
...

Sublime’s Attack Spotlight details a credential-phishing campaign that leverages Google Cloud Application Integration to send authenticated-looking emails and hosts an LLM-generated, multi-challenge CAPTCHA on Google Cloud Storage to filter bots before redirecting victims to credential phishing pages; the report describes the attack flow, the CAPTCHA’s bot-detection and challenge configuration, observed indicators (storage.cloud.google.com links, suspicious URLs, Google impersonation, urgency), and Sublime’s detection signals and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.