Over the past 24 hours, incident responders and threat analysts have been tracking a phishing campaign that feels different—not louder, not sloppier, but cleaner. More than 9,000 emails in a single day were sent using legitimate Google infrastructure, and that’s exactly what makes this campaign dangerous.
This isn’t about spoofed domains or broken email headers. This is about attackers hiding in plain sight.
A Legitimate Feature, Used Illegitimately
At the center of this activity is Google Cloud Application Integration, a platform designed to help businesses automate everyday tasks. One of its features allows workflows to send email notifications—think alerts, approvals, invoices, or system updates.
Attackers realized something important:
they don’t need to build phishing infrastructure if they can borrow trust instead.
By abusing the built-in “Send Email” action, they’re generating emails that are delivered directly by Google systems. From a technical standpoint, these messages are indistinguishable from legitimate automated notifications.
They pass:
- SPF
- DKIM
- DMARC alignment
No forged headers. No sketchy mail servers. Nothing obviously wrong.
What the Emails Look Like
To the recipient, these messages feel routine—almost boring. They resemble standard Google-generated notifications: workflow alerts, shared access notices, or account-related updates. The language is neutral, the formatting is simple, and the sender appears legitimate.
That’s intentional.
There’s no flashy branding or obvious scare tactics. Just enough urgency to encourage a click.
The Real Payload: Microsoft Credential Harvesting
Clicking the link doesn’t immediately raise alarms either. Users are quietly redirected away from Google and land on Microsoft-themed login pages designed to steal credentials—most commonly targeting Microsoft 365 accounts.
These pages mimic real Microsoft sign-in portals with unsettling accuracy:
- Familiar branding
- Clean layouts
- “Session expired” or “Please sign in again” messages
Victims often comply without hesitation. After all, the email came from Google, passed all security checks, and asked them to log into Microsoft—something many people do daily.
Why This Campaign Is So Effective
Security teams have spent years training users to:
- Check the sender
- Look for domain mismatches
- Be suspicious of failed authentication
This campaign breaks those rules.
The infrastructure is real.
The authentication is valid.
The service is legitimate.
Only the intent is malicious.
For email security gateways and SOC teams, this creates a blind spot. Automated defenses often trust messages that originate from well-known providers with clean reputations. End users do the same.
Subtle Clues Defenders Are Catching
Even though the emails are technically “clean,” defenders are beginning to notice patterns:
- Sudden surges in workflow-generated emails
- Generic or oddly named integrations
- Notification content that doesn’t match normal business processes
- Links that redirect through benign-looking URLs before landing on credential pages
These are behavioral signals—not traditional indicators of compromise.
The Bigger Picture
This isn’t just a phishing campaign; it’s a warning. As organizations increasingly rely on cloud automation and no-code platforms, attackers are learning how to blend abuse into normal operations.
The old question—“Is this email authentic?”—is no longer enough.
The new question is harder:
“Is this a legitimate use of an authentic service?”
That’s a much tougher problem to solve.
Final Takeaway
What makes this campaign dangerous isn’t sophistication—it’s subtlety. By abusing trusted platforms instead of fighting against them, attackers are shifting the balance in their favor.
Expect more of this. Once trust becomes a weapon, it doesn’t get put back in the box easily.
