logo

Phishing Attacks Abusing Domains on Google Cloud

ID: 6d09a303-e3f5-5835-9816-00dff3fdca8a

STIX ID: report--6d09a303-e3f5-5835-9816-00dff3fdca8a

Feed Name: Zscaler Security Research Blog

Threat Score
60/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ observed an active phishing campaign using Google Appspot and Web.app subdomains to host convincing, SSL-enabled credential-harvesting pages that impersonate enterprise services (Dropbox, Outlook/OneDrive, DocuSign). Attackers evade detection by offloading core logic to externally hosted, randomly named JavaScript files and minimal landing-page content; the report enumerates dozens of malicious subdomains and multiple attacker-controlled collector URLs receiving stolen credentials, and notes that many of these subdomains were not flagged by VirusTotal at the time of analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.