Google Apps Script
Google Apps Script

TraceX Labs Examines Google Apps Script Abuse Across Phishing, Malware and SEO Campaigns

A new threat intelligence study from TraceX Labs has examined the use of Google Apps Script Web Apps in a range of suspicious online activities, including phishing, fraud, malware distribution, SEO manipulation and malicious redirects.

A service designed to help developers automate tasks and build lightweight web applications is now part of a broader cybersecurity discussion.

TraceX Labs has published a detailed report examining how Google Apps Script Web Apps may be incorporated into different types of online abuse. The research looks at how links created through the platform can appear within wider campaigns and why investigators need to examine the activity surrounding them before deciding whether a resource is malicious.

The report was published on September 30, 2026, and is identified as GLOBAL-026.

Apps Script itself is not the target

Google Apps Script is a legitimate development and automation platform. It can be used to create Web Apps, process incoming requests, generate HTML and connect applications with other Google services.

The TraceX Labs research does not describe Google Apps Script as inherently malicious.

Instead, the concern is the possibility that third parties can incorporate legitimate cloud infrastructure into campaigns targeting users.

A visitor could encounter an Apps Script URL through a search engine, email, social media or a messaging application. Depending on how the Web App has been configured, it may serve as a page or intermediary before the visitor is taken somewhere else.

The risks go beyond traditional phishing

Phishing is one of the major areas examined by the researchers.

The report covers campaigns involving credential harvesting, financial fraud, investment scams, fake employment opportunities, payment-related deception and social engineering.

In these situations, the first URL may only represent one part of the infrastructure.

Investigators may therefore need to examine the destination that follows, the domains connected to the campaign and any files or information delivered to the user.

TraceX Labs also discusses cases involving Android APK distribution and possible malware delivery. The report recommends using technical analysis or reliable threat-reputation sources before classifying a file or campaign as malicious.

SEO manipulation is another concern

The researchers also examined how suspicious infrastructure can be connected to search-engine manipulation.

Pages created primarily to attract search traffic may contain excessive keywords, automatically generated text, duplicated templates or large collections of outbound links.

Other warning signs can include doorway pages and unusual redirect chains.

TraceX Labs notes that activity designed to manipulate search rankings may potentially correspond to T1608.006, SEO Poisoning, in the MITRE ATT&CK framework.

At the same time, the researchers caution that these indicators should be investigated in context rather than used individually as proof of malicious behaviour.

Spam activity takes several forms

The report also examines a variety of spam categories.

These include gambling and betting-related spam, adult and NSFW content, drug-related spam, deepfake and synthetic-media campaigns, search and video spam, and movie-piracy-related activity.

The presence of a particular subject or keyword does not necessarily establish that a website is involved in cybercrime.

TraceX Labs recommends collecting additional evidence and examining how the infrastructure behaves before assigning a classification.

Researchers urge caution with suspected illegal content

Another section of the report addresses suspected CSAM/CSE-related infrastructure.

TraceX Labs classifies these findings as “Suspected / Corroboration Required.” This means the researchers consider additional corroborating evidence necessary.

The report also provides guidance around evidence handling, advising researchers not to unnecessarily download, reproduce or distribute suspected illegal material.

Cloud reputation is not enough to establish trust

One of the central observations in the report is that a well-known cloud provider should not automatically be treated as a guarantee of safe content.

A Google URL does not by itself demonstrate that Google created the content, operates a linked external website or endorses the activity associated with the resource.

The same applies to HTTPS. An encrypted connection helps protect communications, but it does not independently confirm that a website is legitimate.

This distinction can be particularly important during threat investigations, where the hosting provider and the actual operator may be separate entities.

What investigators can look for

TraceX Labs recommends combining different sources of technical evidence when examining suspicious Apps Script activity.

Among the indicators investigators can examine are:

  • Unusual URL parameters
  • Deployment identifiers
  • Redirect destinations
  • Related domains
  • IP addresses
  • ASNs
  • Certificates
  • File hashes
  • Download activity
  • Browser and endpoint telemetry

Web proxy records can help reconstruct the path followed by a user, while endpoint logs may reveal unexpected downloads, file execution or suspicious browser activity.

Connecting these indicators can help researchers determine whether apparently separate URLs are actually part of the same campaign.

Evidence should come before classification

TraceX Labs uses a number of classifications in its research, including Observed, Correlated, Suspected, Potential, Benign and Unknown.

The approach is intended to distinguish what researchers have directly observed from conclusions that require additional evidence.

The report also warns against using a single URL, screenshot or infrastructure indicator to establish criminal intent, ownership, attribution or a connection to Google.

Its suggested investigation model is:

Discover → Validate → Correlate → Classify → Report

This framework encourages researchers to first identify suspicious activity, verify the available evidence and then connect it with other technical information before reaching a classification.

A reminder for organizations using cloud services

The TraceX Labs findings highlight an ongoing challenge for cybersecurity teams: malicious campaigns can potentially make use of legitimate services that organizations already trust.

For businesses, that means security monitoring may need to focus on behaviour rather than simply blocking a particular cloud provider.

Redirects, destination domains, downloaded files, suspicious parameters and links between infrastructure can all provide useful evidence during an investigation.

TraceX Labs says its full report contains additional technical information and recommendations intended for security researchers, SOC teams, CERTs and law-enforcement organizations.

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *

Prove your humanity: 8   +   6   =