Close Menu
    Main Menu
    • Home
    • News
    • Tech
    • Robotics
    • ML & Research
    • AI
    • Digital Transformation
    • AI Ethics & Regulation
    • Thought Leadership in AI

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    5 Methods to Use Cross-Validation to Enhance Time Sequence Fashions

    March 5, 2026

    Why the Hybrid SOC Is Your Subsequent Use of AI

    March 5, 2026

    149 Hacktivist DDoS Assaults Hit 110 Organizations in 16 International locations After Center East Battle

    March 5, 2026
    Facebook X (Twitter) Instagram
    UK Tech InsiderUK Tech Insider
    Facebook X (Twitter) Instagram
    UK Tech InsiderUK Tech Insider
    Home»AI Ethics & Regulation»Menace Actors Exploit Google Apps Script to Host Phishing Websites
    AI Ethics & Regulation

    Menace Actors Exploit Google Apps Script to Host Phishing Websites

    Declan MurphyBy Declan MurphyMay 30, 2025No Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Menace Actors Exploit Google Apps Script to Host Phishing Websites
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link


    The Cofense Phishing Protection Middle has uncovered a extremely strategic phishing marketing campaign that leverages Google Apps Script a respectable improvement platform inside Google’s ecosystem to host misleading phishing pages.

    This assault, masquerading as an bill e-mail, exploits the inherent belief customers place in Google’s trusted surroundings to trick recipients into divulging delicate data.

    A Subtle Phishing Marketing campaign

    By embedding malicious content material inside a good area like script[.]google[.]com, menace actors craft an phantasm of authenticity that bypasses typical suspicion, making this a very insidious type of social engineering.

    – Commercial –
    Google Apps Script
    Phishing Web page

    This marketing campaign underscores the rising sophistication of cybercriminals who’re more and more weaponizing instruments from trusted tech giants to execute their schemes.

    In response to the Cofense Phishing Protection Middle Report, The assault begins with a seemingly innocuous e-mail, spoofing the area of a respectable firm dealing in incapacity and well being tools, presenting itself as an pressing bill.

    The minimalistic design and ambiguous content material of the e-mail are deliberate, aiming to evoke stress or curiosity and immediate recipients to click on on the embedded hyperlink with out hesitation.

    How the Assault Unfolds and Exploits Belief

    Quick emails like these are much less more likely to set off spam filters or reveal errors that may in any other case expose the rip-off.

    Upon clicking the hyperlink, victims are directed to a faux bill web page hosted on Google’s platform, the place a delicate “Preview” button entices additional interplay.

     Google Apps Script
    Pretend Bill Web page

    Clicking this button unveils a fraudulent login window, meticulously crafted to imitate a respectable authentication portal.

    Using Google’s area instills a false sense of safety, exploiting the mindset of “it’s Google, so it have to be protected,” which attackers depend on to reap e-mail credentials and passwords.

    As soon as entered, these credentials are captured by way of a PHP script and transmitted to the attacker, after which the person is seamlessly redirected to a real Microsoft login web page to keep away from suspicion.

    This redirection tactic is a intelligent transfer to delay detection, doubtlessly permitting attackers to infiltrate delicate techniques, resulting in knowledge breaches or monetary losses.

    The marketing campaign exemplifies how respectable platforms may be repurposed for malicious intent, blurring the traces between protected and unsafe digital interactions.

    It highlights the vital want for heightened vigilance, as even trusted domains can function conduits for cybercrime.

    Organizations should prioritize worker training on recognizing such threats and undertake sturdy phishing detection options like Cofense’s Managed Phishing Detection and Response (MPDR) to counter these evolving techniques in real-time.

    Indicators of Compromise (IOC)

    Kind Particulars
    An infection URL hXXps://script[.]google[.]com/macros/s/AKfyc…/exec?…outlook[.]office365[.]com/Encryption/msi2auth64
    An infection IPs 142.251.16.106, 142.251.16.147, 142.251.16.104, 142.251.16.105, 142.251.16.99, 142.251.16.103
    Payload URL hXXps://solinec[.]com/APi/1YjDl_aUXTsHrhxiufjU0fBe4d2wsameerm3wJl_LX[.]php
    Payload IP 167.250.5.66

    Discover this Information Fascinating! Observe us on Google Information, LinkedIn, & X to Get Prompt Updates!

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Declan Murphy
    • Website

    Related Posts

    149 Hacktivist DDoS Assaults Hit 110 Organizations in 16 International locations After Center East Battle

    March 5, 2026

    CISA Warns Qualcomm Chipsets Reminiscence Corruption Vulnerability Is Actively Exploited in Assaults

    March 4, 2026

    Iranian cyberattacks fail to materialize however risk stays acute

    March 4, 2026
    Top Posts

    5 Methods to Use Cross-Validation to Enhance Time Sequence Fashions

    March 5, 2026

    Evaluating the Finest AI Video Mills for Social Media

    April 18, 2025

    Utilizing AI To Repair The Innovation Drawback: The Three Step Resolution

    April 18, 2025

    Midjourney V7: Quicker, smarter, extra reasonable

    April 18, 2025
    Don't Miss

    5 Methods to Use Cross-Validation to Enhance Time Sequence Fashions

    By Yasmin BhattiMarch 5, 2026

    On this article, you’ll be taught 5 sensible cross-validation patterns that make time sequence analysis…

    Why the Hybrid SOC Is Your Subsequent Use of AI

    March 5, 2026

    149 Hacktivist DDoS Assaults Hit 110 Organizations in 16 International locations After Center East Battle

    March 5, 2026

    Black Forest Labs' new Self-Circulation approach makes coaching multimodal AI fashions 2.8x extra environment friendly

    March 5, 2026
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    UK Tech Insider
    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms Of Service
    • Our Authors
    © 2026 UK Tech Insider. All rights reserved by UK Tech Insider.

    Type above and press Enter to search. Press Esc to cancel.