logo

Threat actors abuse Google Apps Script in evasive phishing attacks

ID: 2ed85cb9-f15e-5d85-a07c-d59119023479

STIX ID: report--2ed85cb9-f15e-5d85-a07c-d59119023479

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2025-05-29

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Threat actors are abusing Google Apps Script to host realistic, credential-harvesting phishing pages on script.google.com. Emails with invoice or tax lures lead victims to the Google-hosted fake login, capture credentials which are exfiltrated, and then redirect victims to the legitimate site to reduce suspicion; security teams are advised to scrutinize or block Google Apps Script URLs and adjust email security policies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.