Threat Actors Exploit Google Services in Elaborate Impersonation Scheme
A new and highly engineered cyberattack is actively deceiving Google users by mimicking legal demands from law enforcement. This scheme takes advantage of Google’s own tools to craft urgent, realistic-looking notices that evade detection and manipulate recipients into compliance.
The operation cleverly repurposes authentic components of Google’s infrastructure—such as the OAuth authorization framework and the sites.google.com domain—to deliver phishing emails that seem to originate from Google’s legitimate no-reply@accounts.google.com address.
Victims are first struck by a jarring message asserting that Google has received a formal legal order—such as a subpoena—compelling access to their private account data. These emails are laced with official-sounding language, case numbers, and mock support references, all designed to reinforce the illusion of credibility. Embedded links lead to pages styled to resemble genuine Google support portals, pushing targets toward dangerous actions under the guise of urgency.

Impersonated Google Help Page (Credit: Kaspersky)
The fear of legal repercussions triggers a sense of urgency, prompting users to react instinctively rather than rationally—making them far more susceptible to clicking before questioning the legitimacy of the alert.

Spoofed Email Appears Legitimate, Sent via Google Infrastructure (Image Credit: Kaspersky)
A striking aspect of this campaign is its use of authentic Google infrastructure to distribute malicious messages. These emails, while fraudulent in intent, are actually delivered through Google’s own systems and bear valid digital signatures from accounts.google.com—a tactic that gives them a deceptive layer of credibility.
Researchers at Kaspersky have flagged this method as a groundbreaking evolution in phishing tactics, one that harnesses the authority of trusted cloud services to bypass traditional filters and sow confusion among recipients.
The attackers’ strategy is technically intricate. It starts with registering a domain that closely imitates Google’s system-generated domain patterns—something like googl-mail-smtp-out-198-142-125-38-prod.net. Once that’s in place, they use this domain to create a legitimate-looking email address and enroll it into a trial instance of Google Workspace.
“This operation reveals a deep understanding of cloud platform dynamics,” said security expert Alanna Titterington, who tracked the activity. “It’s a rare case of cybercriminals bending a trusted ecosystem to do their bidding while appearing completely aboveboard.”
How the Exploit Works
The campaign hinges on subtle gaps in how OAuth apps within Google’s ecosystem are authenticated and authorized. Misconfigurations or lack of rigorous verification processes can create an opening—one these attackers have weaponized to full effect.

Abusing Google OAuth to Smuggle Phishing Content (Image Credit: Kaspersky)
Cybercriminals have discovered a loophole in Google’s OAuth app registration process, turning a benign feature into a powerful delivery vector for phishing attacks.
At the heart of the exploit is the “App Name” field—normally used to label third-party applications requesting access. However, attackers are leveraging its unrestricted input capabilities to embed entire phishing narratives, including clickable malicious links, directly into this field.
Here’s how the manipulation unfolds:
During app setup, attackers insert their phishing message—complete with URLs—into the app name. Once saved, Google’s infrastructure automatically sends a system-generated security alert from the trusted no-reply@accounts.google.com address, which includes the malicious app name in its content.
This signed email—originating from a verified Google domain—is then rerouted to multiple targets using email forwarding tools, retaining its cryptographic signature and bypassing conventional email security filters.
Victims who engage with the message are first funneled through genuine Google login portals. This adds a layer of perceived authenticity. If already signed in, they’re taken directly to a malicious support page hosted on sites.google.com, a legitimate Google platform often used for personal or business sites—making the threat harder to detect.
Following Kaspersky’s findings, Google has acknowledged the abuse of this system and is reportedly working on changes to mitigate the vulnerability. However, a formal patch or timeline for resolution has not yet been provided.




