Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
phishing-campaign-intelligencecredential-access-methodidentity-impersonation-frauddefense-evasion-method

Phishing Campaign Abuses Google Cloud Application Integration to Impersonate Google Emails

Updated 3mo agoFirst seen Jan 2, 20267 sources

Cybercriminals have launched a sophisticated phishing campaign that exploits Google Cloud's Application Integration service to send emails that closely mimic legitimate Google notifications. By leveraging the service's "Send Email" task, attackers are able to distribute messages from the trusted noreply-application-integration@google.com address, effectively bypassing traditional email security measures such as DMARC and SPF. The phishing emails are crafted to resemble routine enterprise communications, including voicemail alerts and file access requests, increasing the likelihood that recipients will trust and interact with them. Over a two-week period, nearly 9,400 phishing emails targeted approximately 3,200 organizations across the U.S., Asia-Pacific, Europe, Canada, and Latin America.

The attack chain employs a multi-stage redirection process to evade detection and maximize credential theft. Initial links in the emails direct users to legitimate Google Cloud URLs (storage.cloud.google.com), followed by a redirection to googleusercontent.com where a fake CAPTCHA is presented to bypass automated scanners. The final stage leads victims to a counterfeit Microsoft login page hosted on a non-Microsoft domain, designed to harvest user credentials. This campaign demonstrates the increasing abuse of trusted cloud infrastructure for phishing, highlighting the need for organizations to scrutinize even seemingly authentic emails originating from reputable domains.

Share:
Phishing Campaign Abuses Google Cloud Application Integration to Impersonate Google Emails
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Jan 2, 20266mo ago

Google blocks the email-feature abuse and adds protections

Google confirmed the attackers had misused a workflow automation tool and stated that its infrastructure was not compromised. The company said it had blocked the abuse of the notification capability and implemented additional safeguards against this attack path.

Researchers detect and publicly disclose the Google cloud phishing campaign

On January 2, 2026, multiple security reports disclosed the campaign after researchers including Check Point identified nearly 9,400 phishing emails sent over roughly two weeks. The disclosures highlighted abuse of Google's workflow automation tools rather than a compromise of Google's infrastructure.

Dec 1, 20257mo ago

Attackers use multi-stage Google-hosted redirects to steal credentials

During the campaign, victims were routed through trusted Google services such as Google Cloud Storage and googleusercontent.com, sometimes via fake CAPTCHA or verification pages, before reaching counterfeit Microsoft 365 or Google login pages. The technique helped the phishing emails bypass SPF, DMARC, and reputation-based defenses while harvesting credentials and, in some cases, enabling OAuth abuse.

Phishing campaign abuses Google Cloud email features in December 2025

In December 2025, attackers launched a large-scale phishing campaign using Google Cloud Application Integration to send emails from legitimate Google-owned addresses. The operation targeted more than 3,000 organizations or customers across multiple regions and industries, especially manufacturing, technology, finance, and related sectors.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

14 LINKEDOpen in app
Affected products
5 linked
Google ClassroomGoogle ClassroomGoogle ClassroomGoogle ClassroomAzure Active Directory
Organizations
9 linked
GoogleMicrosoft CorporationMalwarebytesSalesforceCheck Point Software TechnologiesAmazon Web ServicesRavenMailRescanaAmazon SES
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.