TraceX Labs Examines Google Apps Script Abuse Linked to Phishing, Malware, SEO Spam and Suspected CSAM Infrastructure

Cybersecurity research firm TraceX Labs has published a new threat intelligence report examining the potential abuse of publicly accessible Google Apps Script Web Apps in campaigns involving phishing, online fraud, malware distribution, SEO manipulation, spam, malicious redirection and other forms of suspicious infrastructure activity.

The report, titled Abuse of Google Apps Script Web Apps for Phishing, Fraud, Malware Distribution, SEO Manipulation, Spam, CSAM/CSE-Related Abuse and Malicious Redirection,is identified as GLOBAL-026 and dated September 30, 2026. TraceX Labs has assigned the investigation an overall High threat assessment and marked its status as Active / Monitoring.

Google Apps Script Used as an Intermediate Layer

Google Apps Script is a legitimate development and automation platform used for applications, education, data processing and Google Workspace workflows. TraceX Labs does not allege that Google is involved in or responsible for the activity described in the report.

Instead, the investigation examines how publicly accessible Apps Script Web Apps could potentially be used as an intermediate infrastructure layer.

According to the report, these web applications can process HTTP requests, generate HTML, handle parameters, interact with external resources and participate in redirect workflows. In some investigated scenarios, a user may encounter a URL through a search engine, social media platform, email or messaging service before reaching an Apps Script endpoint.

The endpoint may subsequently display a landing page, dynamically generated content or redirect the visitor to external infrastructure.

Phishing, Fraud and Malware Distribution

The report examines several cybersecurity abuse categories associated with the investigated infrastructure, including phishing, credential harvesting, malicious APK distribution, malware delivery, social engineering and malicious redirects.

TraceX Labs also investigated examples involving financial and employment-related scams, including investment schemes, fraudulent payment pages, UPI-related fraud, cryptocurrency-related activity, impersonation and fake recruitment campaigns.

According to the report, some investigated Apps Script pages contained APK download links or redirected users toward infrastructure associated with suspicious payloads. TraceX Labs describes these findings as observed or correlated evidence, rather than treating every Apps Script deployment as malicious.

The investigation also includes examples of investment and recruitment-related landing pages. Reported indicators included payment requests, requests for personal information, unrealistic salary claims and contact through external messaging platforms.

SEO Manipulation and Search Spam

Another area examined by the report is the potential use of Apps Script infrastructure for search-engine spam and SEO manipulation.

TraceX Labs identifies indicators including keyword-heavy landing pages, doorway pages, automatically generated content, large numbers of outbound links, repeated page templates, redirect chains, commercial affiliate links and campaign-specific URLs.

Where search visibility is deliberately manipulated, the report links the behaviour to MITRE ATT&CK technique T1608.006, Stage Capabilities: SEO Poisoning.

The investigation also examines search and video spam associated with movie-piracy-related keywords. TraceX Labs notes that such ecosystems may contain advertising, redirects, malvertising or malware-delivery infrastructure, while stressing that individual copyright classifications require separate assessment.

Spam, Gambling and Synthetic-Media Campaigns

The report covers additional categories of suspicious activity, including adult-content spam, gambling and betting spam, drug-related search spam, deepfake and synthetic-media campaigns and automated or AI-assisted content generation.

Investigated examples reportedly included gambling-related keywords, casino promotions, affiliate links and redirects. Some campaigns also combined adult-content and gambling-related material.

TraceX Labs separately examined infrastructure associated with deepfake and synthetic-media content, including manipulated-media claims, fake celebrity material and external distribution platforms.

The report cautions that the presence of a particular keyword does not by itself establish illegal activity. Drug-related keywords, for example, require examination of the actual content, destination infrastructure, transaction mechanisms and applicable legal context.

Suspected CSAM/CSE-Related Infrastructure

One of the most sensitive areas covered by the report concerns infrastructure that TraceX Labs categorises as potentially related to child sexual exploitation (CSE) and child sexual abuse material (CSAM).

TraceX Labs classifies the relevant findings as /Suspected / Corroboration Required/, indicating that additional evidence would be necessary before making a definitive determination.

The report recommends enhanced evidence-handling procedures for such investigations. It specifically advises investigators not to unnecessarily download, reproduce or redistribute suspected CSAM/CSE or NCII-related material and recommends using appropriately redacted evidence for public reporting.

The report also discusses non-consensual intimate imagery (NCII) and sextortion as sensitive investigative categories. The impact classifications used in the report describe potential investigative impact and do not establish that every deployment examined caused each listed harm.

A Google-Hosted URL Does Not Automatically Establish Legitimacy

A central point of the report is that the reputation of a trusted cloud provider should not, by itself, determine whether a particular URL or campaign is safe.

TraceX Labs notes that a Google-owned URL does not establish that Google created, endorsed or operates the content hosted or referenced through that URL. Similarly, the presence of HTTPS indicates encrypted communication but does not independently establish that a website or destination is legitimate.

The report therefore recommends analysing the behaviour of the URL, its redirects, final destinations and associated infrastructure instead of treating all Google-hosted infrastructure as malicious or legitimate solely because of its hosting provider.

Recommended Detection Approach for Security Teams

TraceX Labs proposes a defensive monitoring strategy covering URL analysis, web proxies, endpoint security and threat intelligence.

Security teams are advised to monitor suspicious Apps Script URLs, unusual parameters, repeated deployment identifiers, known malicious destinations and campaign-specific URL patterns.

At the web-proxy level, investigators can examine redirect chains, final destinations, downloaded file types, MIME types and browser behaviour. Endpoint monitoring can be used to identify suspicious APK downloads, credential submissions and unusual execution activity.

The report also recommends correlating Apps Script URLs with destination domains, IP addresses, autonomous system numbers, certificates, URL parameters, file hashes and related campaign infrastructure.

TraceX Labs emphasises that multiple independent indicators should increase investigative priority, while no single indicator should automatically result in a malicious classification without contextual validation.

Report Highlights Evidence Limitations

The report acknowledges that Google Apps Script has extensive legitimate use and that URL structure alone cannot establish malicious intent.

Other limitations identified by TraceX Labs include changing search-engine indexing, rapidly disappearing infrastructure, user-agent or location-dependent redirects and potential false positives from third-party reputation services.

To address these limitations, the report recommends classifying findings according to available evidence using categories such as Observed, Correlated, Suspected, Potential, Benign and Unknown.

The framework is intended to distinguish technical capabilities or suspicious indicators from confirmed malicious behaviour.

TraceX Labs Calls for Behaviour-Based Infrastructure Analysis

In its final assessment, TraceX Labs argues that legitimate cloud-hosted application infrastructure can create challenges for threat intelligence and defensive detection when incorporated into abusive campaigns.

The report examines potential activity involving SEO poisoning, doorway pages, spam, fraud, phishing, malware distribution, malicious redirection, adult-content spam, NCII, sextortion and suspected CSE/CSAM-related infrastructure. It also discusses gambling, drug-related, deepfake, video-search and movie-piracy-related spam.

The recommended investigative model is:

Discover/Validate/Correlate/Classify/Report

According to TraceX Labs, security teams should assess infrastructure using its behaviour, content, destinations and relationships with other campaign indicators rather than relying solely on the reputation of the hosting provider.

The complete GLOBAL-026 Threat Intelligence Report is available on the TraceX Labs website.