Abusing App Engine to Automate Phishing

Stu Sjouwerman | Sep 24, 2020

app phishing attackAttackers can abuse a feature in Google App Engine to generate unlimited phishing URLs, BleepingComputer reports. Security researcher Marcel Afrahim found that App Engine URLs that contain a non-existent subdomain will redirect the user to the app’s default page, rather than displaying a 404 error. As long as the “project ID” portion of the URL is correct, any App Engine URL will redirect to that particular project.

Many security products rely on blocking known malicious or suspicious URLs, but this technique allows attackers to generate a random, new URL for every single attack. This technique can be used for phishing attacks as well as for downloading malware payloads without being flagged by email filters or security products. Afrahim demonstrates how this can easily be automated with a few lines of code.

“And now you have a script that downloads the payload from different URL hostnames each time [it] is run and would render the network IOC of such hypothetical sample absolutely useless,” Afrahim writes.

Additionally, since these apps are hosted on Google’s infrastructure, some users could be fooled into thinking they’re actually trusted by Google.

“The fact that a single malicious app is now represented by multiple permutations of its subdomains makes it hard for sysadmins and security professionals to block malicious activity,” BleepingComputer explains. “But further, to a technologically unsavvy user, all of these subdomains would appear to be a ‘secure site.’ After all, the appspot.com domain and all its subdomains come with the seal of ‘Google Trust Services’ in their SSL certificates.”

Afrahim notes that at least one phishing campaign is already using this technique, and more can be expected to follow. Attackers will always find new ways to exploit flaws or abuse features to bypass security technology. New-school security awareness training can help your employees avoid falling for phishing attacks and other forms of social engineering.

BleepingComputer has the story.

Topics: Phishing

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the human and AI workforce to make safer security decisions every day. Trusted by over 70,000 organizations worldwide, we help strengthen security culture and manage risk. Our comprehensive AI-driven platform includes awareness and compliance training, cloud email security, real-time coaching, crowdsourced anti-phishing, AI Defense Agents, agent security and more. As the only global security platform of its kind, KnowBe4 provides personalized content, tools, and techniques to keep the modern workforce safe from phishing, vishing, deepfakes, and emerging threats.

Get the latest insights, trends and security news. Subscribe to CyberheistNews.