Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Firebase, Google Apps Script Abused in Fresh Phishing Campaigns

Firebase, Google Apps Script Abused in Fresh Phishing Campaigns

Posted on May 30, 2025May 30, 2025 By CWS

Cybersecurity researchers are calling consideration to 2 not too long ago noticed phishing campaigns caught abusing the respectable companies Firebase and Google Apps Script to lure unsuspecting customers to malicious content material.

In mid-Could, Trellix stated it recognized a spear-phishing operation impersonating a Rothschild & Co worker to focus on monetary executives at banks and vitality, insurance coverage, and funding organizations in Africa, Canada, Europe, the Center East, and South Asia.

The malicious emails contained a faux brochure, recognized as a webpage hosted on Firebase and hidden behind a math-quiz customized CAPTCHA. As soon as the problem is solved, the sufferer is served a ZIP file that accommodates a VBS script.

The script was designed to silently set up NetBird and OpenSSH on the sufferer’s system, to create a hidden local-admin account, and to allow RDP, offering the attackers with distant entry to the machine.

The multi-stage assault was designed to evade detection from each defensive options and people alike, and to make sure persistent entry to sufferer machines by means of the respectable distant entry instrument NetBird, probably with devastating impression, in response to Trellix.

Alongside the Trellix repoort, Cofense publicly documented one other phishing marketing campaign designed to evade detection by means of the abuse of Google Apps Script, a respectable growth platform built-in throughout varied merchandise from the tech large.

Spoofing the respectable area of a incapacity and well being gear supplier, the marketing campaign depends on phishing emails designed to create a way of urgency and mislead the recipient into clicking a faux bill hyperlink that takes them to an bill web page hosted Google Apps Script.

“By internet hosting the phishing web page inside Google’s trusted surroundings, attackers create an phantasm of authenticity. This makes it simpler to trick recipients into handing over delicate data,” Cofense stated.Commercial. Scroll to proceed studying.

The phishing web page directs the consumer to click on a ‘preview’ button that triggers a faux login window pop-up, mimicking a respectable Microsoft login web page. Your entire setup is hosted on script[.]google[.]com, which is supposed to supply customers with a way of belief, Cofense notes.

Particulars on the 2 campaigns got here to mild proper after ESET warned of phishing assaults impersonating the favored e-signature agency Docusign. Recipients obtain e-mail messages with a spoofed Docusign envelope requesting them to assessment a doc or scan a QR code, which leads them to a faux Microsoft login web page.

Associated: Legacy Google Service Abused in Phishing Assaults

Associated: China-Linked APT41 Exploits Google Calendar to Goal Governments

Associated: M-Developments 2025: State-Sponsored IT Staff Emerge as World Risk

Associated: Many Malware Campaigns Linked to Proton66 Community

Security Week News Tags:Abused, Apps, Campaigns, Firebase, Fresh, Google, Phishing, Script

Post navigation

Previous Post: US Sanctions Philippine Company for Supporting Crypto Scams
Next Post: Countering Spear Phishing with Advanced Email Security Solutions

Related Posts

In Other News: FBI Warns of BadBox 2, NSO Disputes WhatsApp Fine, 1,000 Leave CISA In Other News: FBI Warns of BadBox 2, NSO Disputes WhatsApp Fine, 1,000 Leave CISA Security Week News
In Other News: k Google Cloud Build Flaw, Louis Vuitton Breach Update, Attack Surface Growth In Other News: $30k Google Cloud Build Flaw, Louis Vuitton Breach Update, Attack Surface Growth Security Week News
HPE AOS-CX Flaw Allows Admin Password Resets HPE AOS-CX Flaw Allows Admin Password Resets Security Week News
Apono Raises  Million for Cloud Identity Management Platform Apono Raises $34 Million for Cloud Identity Management Platform Security Week News
689,000 Affected by Insider Breach at FinWise Bank 689,000 Affected by Insider Breach at FinWise Bank Security Week News
Malicious Chrome Extensions Compromise User Data Malicious Chrome Extensions Compromise User Data Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Vulnerability in MongoDB Risks Data Exposure
  • Windows Zero-Day Exploits: YellowKey and GreenPlasma Revealed
  • Fragnesia Linux Kernel Vulnerability Allows Root Access
  • NGINX Vulnerability Allows Remote Code Execution
  • Critical 18-Year NGINX Vulnerability Enables Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Vulnerability in MongoDB Risks Data Exposure
  • Windows Zero-Day Exploits: YellowKey and GreenPlasma Revealed
  • Fragnesia Linux Kernel Vulnerability Allows Root Access
  • NGINX Vulnerability Allows Remote Code Execution
  • Critical 18-Year NGINX Vulnerability Enables Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark