Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    What is MicroSD Express? Everything You Need To Know

    June 8, 2025

    5 to avoid pressure washing mistakes

    June 8, 2025

    Spain vs Portugal Live Stream: How to see the Rashtra League Final 2025 from anywhere and for free

    June 8, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Threat actor Google apps script misuses the script
    Security

    Threat actor Google apps script misuses the script

    PineapplesUpdateBy PineapplesUpdateMay 29, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Threat actor Google apps script misuses the script
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Threat actor Google apps script misuses the script

    The danger actor is misusing the ‘Google Apps Script’ Vikas Manch, which is to host the fishing page that appears valid and steal login credentials.

    This new trend was observed by security researchers in Coffee, warning that the fraud login window “is carefully designed to look like a valid login screen.”

    “The attack uses an email as an invoice, which contains a link to a webpage that uses the Google Apps script, which is a growth platform integrated into the suite of Google’s products,” Coffeens explains,

    “By hosting the fishing page within the reliable environment of Google, the attackers create confusion of authenticity. This makes it easier to hand over sensitive information to the recipients.”

    Lawful service abuse

    The Google Apps script is a JavaScript-based cloud scripting platform from Google that allows users to automate tasks and expand the functionality of Google work area such as Google Sheets, Doors, Drivers, Drives, Gmail and Calendar.

    These scripts run on a reliable Google domain under “Script.google.com”, which is permission for most security products.

    The attackers write a Google Apps script that displays a fake login page to record credentials. The data is connected to the attacker’s server through a hidden request.

    Fishing page hosted on google infrastructure
    Fishing page hosted on google infrastructure
    Source: Cofense

    Since the platform allows anyone to publish a script with an account as a public web app, gives it a Google Domain, the danger actor can easily share it through a fishing email with the victims that will not trigger any warnings.

    The fishing email consists of an invoice payment or tax-related call for action for the recipient, which is associated with malicious Google-hosted fishing page.

    Sample of fishing emails used in attacks
    Sample of fishing emails used in attacks
    Source: Cofense

    After entering his user name and password, they are redirected to the legitimate service that was spoiled for less doubt and gives time to danger actors to take advantage of the stolen data.

    Google Apps seems to be a new focus of script fishing actors who seek valid platforms to misuse for theft and operational efficiency.

    In this case, it also gives flexibility to the attackers to adjust your script from a distance without sending a new link, switching to a different greed without any effort.

    An effective defense remedy must configure email safety to check the cloud service link and if possible, block access to Google Apps script completely, or at least flagged them as potentially dangerous.

    Bleepingcomputer has approached Google whether they are planning to implement any opponent misuse measures in response to Cofense’s findings, but we have not heard back as publication.


    Red Report 2025

    Based on the analysis of 14M malicious tasks, search for the top 10 MITERAT & CK techniques behind the 93% attacks and how to defend them against them.

    actor apps Google misuses script threat
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleHow to unlock Roblox to train your dragon dragon – gamezebo
    Next Article 7 days until the doors open in session: AI
    PineapplesUpdate
    • Website

    Related Posts

    Gaming

    Princess Peach’s voice has been replaced by the actor after 18 years

    June 8, 2025
    Security

    Remove project directors presented as malicious NPM package utilities

    June 8, 2025
    Security

    Supply series attacks Glustac NPM package with 960K weekly download

    June 7, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025594 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025536 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025465 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Meta delay entrusts ‘Bhamoth’ AI model, Openi and Google more than one more head start

    May 16, 20250 Views

    The OURA ring found a new rival with just one titanium design and 24/7 biometric tracking – no membership is required

    May 16, 20250 Views

    Filecoin, Lockheed Martin Test IPFS in space

    May 16, 20250 Views
    Our Picks

    What is MicroSD Express? Everything You Need To Know

    June 8, 2025

    5 to avoid pressure washing mistakes

    June 8, 2025

    Spain vs Portugal Live Stream: How to see the Rashtra League Final 2025 from anywhere and for free

    June 8, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.