216.73.217.22

Behind the Script: Unmasking Phishing Attacks Using Google Apps Script

· Published 04/06/2025 20:39 · Modified 05/06/2025 00:46

Export JSON

Essential information

Published
04/06/2025 20:39
Modified
05/06/2025 00:46
Tags
2025-06-04 credential-theft email spoofing google apps script invoice scam microsoft login phishing social engineering
Related entities
2 observables, 3 techniques (mitre)

Description

A sophisticated campaign has been identified that leverages to create a false sense of security. The attack begins with an email masquerading as an invoice, containing a link to a webpage hosted on Google's trusted environment. When clicked, the link redirects to a fake invoice page, followed by a fraudulent login window designed to capture credentials. The use of Google's domain (script.google.com) adds credibility to the scam, making it more likely for users to fall victim. Once credentials are entered, they are transmitted to the attacker, and the user is redirected to a legitimate page to avoid suspicion. This technique demonstrates how threat actors are exploiting trusted platforms to make their attacks more convincing and effective.

External references