Phishing campaign hijacks Google Firebase storage

(Image credit: Shutterstock / Askobol)

Organisations worldwide are under serious threat from credential phishing campaigns. With the continuing growth of cloud technologies, threat actors are finding more and more innovative ways to harvest victims’ company credentials, which are then used to gain a corporate foothold.

A recent campaign uses Google Firebase storage URLs to harvest the victims’ information. Firebase Storage is backed by Google Cloud Storage and provides secure uploads and downloads of files for Firebase apps. The URLs are embedded in the phishing emails. 

While this campaign appears low in volume at the moment, it appears to target certain industries. The major lures include actions such as raising payment invoice, upgrading email account, releasing pending messages, verifying the account, changing password and more. 

Phishing attack

Using the COVID-19 pandemic and internet banking as a pretext, scammers lure the victims into clicking on a fake vendor payment form leading to the phishing page hosted on Firebase Storage.

In another example, a fake account deactivation phishing email is sent to victims, prompting them to click a link which takes them to an Office 365 phishing page hosted on Firebase Cloud Storage.

In subsequent iterations of this scheme, there are also fake bank emails to customers. The fake bank pages are also hosted on Google Firebase cloud storage, where customer/company information is harvested by scammers. 

Credentials harvested as a result of phishing are often used as an initial trigger for launching more advanced attacks. This is another example of scammers leveraging cloud infrastructure for their phishing attacks.

TOPICS
Jitendra Soni

Jitendra has been working in the Internet Industry for the last 7 years now and has written about a wide range of topics including gadgets, smartphones, reviews, games, software, apps, deep tech, AI, and consumer electronics.  

Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)