TraceX Labs has published a new threat intelligence report warning that Google Apps Script Web Apps are being misused in phishing, fraud, malware distribution, SEO spam and malicious redirection campaigns.
Google Apps Script is widely used by developers and businesses to automate tasks and build lightweight web applications connected to Google services. However, a new report from cybersecurity research firm TraceX Labs highlights how the same infrastructure can potentially be incorporated into malicious online campaigns.
The report, released on September 30, 2026, is titled “Abuse of Google Apps Script Web Apps for Phishing, Fraud, Malware Distribution, SEO Manipulation, Spam, CSAM/CSE-Related Abuse and Malicious Redirection.” TraceX Labs has classified the research as GLOBAL-026 and assigned it a high threat assessment.
How Google Apps Script Can Be Abused
According to TraceX Labs, Apps Script Web Apps can receive web requests, process information, display HTML content and communicate with external services. These capabilities make them useful for legitimate automation but can also make them part of abuse chains.
In some campaigns, a user may encounter an Apps Script URL through a search engine, social media post, email or messaging platform. The page can then act as an intermediate step before sending the visitor to another website.
TraceX Labs stresses that this does not mean Google Apps Script itself is a malicious service. Instead, the concern is how legitimate cloud infrastructure can be incorporated into campaigns operated by third parties.
Phishing and Online Fraud Among Key Concerns
The report examines several types of online fraud, including phishing, credential theft, investment scams, employment scams, fake payment schemes and social engineering.
Apps Script Web Apps may potentially be used as landing pages or redirectors in these campaigns. Researchers are therefore advised to examine what happens after a user visits the Apps Script URL rather than treating the URL alone as proof of malicious activity.
The report also discusses cases involving Android APK distribution and potential malware delivery. TraceX Labs recommends using technical analysis and reliable reputation information when making malware-related assessments.
SEO Spam and Search Manipulation
Another major area highlighted by the research is SEO manipulation.
TraceX Labs identifies several patterns that may require further investigation, including:
- Keyword-stuffed pages
- Automatically generated content
- Doorway pages
- Large-scale template duplication
- Excessive outbound links
- Suspicious redirect chains
- Pages designed primarily to influence search rankings
The researchers note that activity intended to manipulate search visibility may potentially correspond with MITRE ATT&CK technique T1608.006, SEO Poisoning.
However, the report recommends examining the complete infrastructure and campaign behaviour instead of automatically classifying every suspicious Apps Script page as malicious.
Spam Campaigns Extend Beyond Phishing
The research also covers other forms of potentially abusive activity found around cloud-hosted infrastructure.
These include gambling and betting spam, adult or NSFW spam, drug-related content, synthetic-media and deepfake spam, video and search spam, as well as movie-piracy-related search activity.
TraceX Labs cautions that the presence of a particular keyword or topic does not automatically demonstrate criminal activity. Investigators need additional evidence and context before assigning a classification.
Report Discusses Suspected CSAM-Related Infrastructure
A separate section of the report addresses suspected CSAM/CSE-related infrastructure.
TraceX Labs categorizes this area as “Suspected / Corroboration Required,” indicating that the available evidence should not be treated as conclusive without further verification.
The report also recommends responsible evidence handling and warns researchers against unnecessarily downloading, reproducing or distributing suspected illegal material.
Google Ownership Does Not Automatically Mean a Page Is Safe
One of the important points raised by TraceX Labs is that the reputation of a cloud provider should not be treated as proof that every resource hosted through its infrastructure is trustworthy.
A Google-owned URL does not necessarily mean Google created the content, operates an external destination or endorses websites linked through the page. Similarly, the presence of HTTPS only confirms encrypted communication and does not independently establish that the content itself is legitimate.
This distinction can be important for security teams investigating suspicious URLs.
Security Teams Should Investigate the Full Redirect Chain
TraceX Labs recommends that security researchers and SOC teams examine Apps Script URLs alongside the infrastructure connected to them.
Potential indicators include unusual URL parameters, recurring deployment identifiers, suspicious destination websites and known malicious infrastructure.
Security teams can also review web proxy logs to identify redirect chains, downloaded files and final destinations. Endpoint telemetry may provide additional clues, such as unexpected APK downloads, suspicious file execution or browser-based credential submissions.
Researchers can correlate URLs with:
- Destination domains
- IP addresses
- Autonomous System Numbers (ASNs)
- Certificates
- URL parameters
- File hashes
- Related campaign infrastructure
TraceX Labs Calls for Evidence-Based Classification
The report uses several classifications, including Observed, Correlated, Suspected, Potential, Benign and Unknown.
TraceX Labs emphasizes that a single URL, screenshot or infrastructure component should not automatically be interpreted as proof of criminal intent, ownership, attribution or affiliation with Google.
Instead, the report recommends a structured investigation process:
Discover → Validate → Correlate → Classify → Report
The approach is designed to help security researchers, SOC teams, CERTs and law enforcement distinguish between legitimate cloud applications and infrastructure that may be participating in a broader malicious campaign.
What the Report Means for Security Researchers
The findings highlight a broader cybersecurity challenge: attackers can potentially use legitimate cloud services as components of malicious infrastructure.
For defenders, this means that blocking an entire cloud platform may not always be an effective approach. Examining behaviour, redirects, destinations, content and relationships between different infrastructure components can provide more useful evidence.
TraceX Labs’ report provides additional technical details, detection recommendations and investigation guidance for organizations dealing with suspicious Google Apps Script Web Apps.
Source: https://tracexlabs.com/reports/google-apps-script-abuse-threat-report-2026.html

