Phishing Campaign Uses Google Cloud to Host Malicious Redirects via GCS Bucket
ID: 232a87af-b498-5bf4-bd3b-56c9abc92d94
STIX ID: report--232a87af-b498-5bf4-bd3b-56c9abc92d94
Feed Name: GBHackers
A phishing campaign is abusing Google Cloud Storage (storage.googleapis.com/googleapis.com) by hosting a redirector (bucket 'whilewait' and file 'comessuccess.html') that appears legitimate to email filters and routes victims to fraudulent payment or malware distribution pages to harvest credit card data; researchers observed 25+ samples using diverse social-engineering lures and recommend verifying redirect chains, scrutinizing sender metadata, and reporting the malicious bucket to Google Cloud Abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
