Wednesday, September 16, 2026
Follow on LinkedIn

Phishing Campaign Exploits Google Cloud to Host Malicious Redirects via GCS Bucket

A highly organized phishing campaign has been discovered, one that abuses Google Cloud Storage (GCS) to host malicious redirect links designed to bypass standard email security filters.

By placing harmful content on a legitimate Google-owned domain, attackers have managed to make fraudulent emails appear trustworthy enough to pass through inbox defenses and reach unsuspecting victims without raising any immediate alarms.

The campaign first came to light in early March 2026, when security researchers began noticing an unusually high volume of phishing emails all pointing to the same destination.

More than 25 distinct phishing emails were found targeting a single user account, each one leading to a URL hosted on storage.googleapis.com.

The consistency of the destination, despite the wide variety of email themes used, pointed clearly to a coordinated operation running through a single piece of cloud infrastructure fully controlled by the attackers.

A threat hunter and malware analyst, Anurag identified the full scope of this campaign through careful inbox monitoring and thorough SMTP header analysis.

By examining over two dozen email samples in detail, he traced every phishing path back to a single GCS bucket named “whilewait,” which contained a file called comessuccess.html — the quiet engine driving every redirect in this operation.

Sample Phishing Email Impersonating a Gmail Subscription Service Alert (Source - Malwr-Analysis)
Sample Phishing Email Impersonating a Gmail Subscription Service Alert (Source – Malwr-Analysis)

The emails themselves covered a broad range of social engineering themes. Some warned recipients that their cloud storage was nearly full or that their antivirus subscription had expired, while others offered fake prize rewards from recognizable brands like T-Mobile, Lowe’s, and State Farm.

Regardless of the theme used, every email pushed the victim toward the same GCS-hosted link, which then silently redirected the browser to a separate, third-party malicious site.

Phishing Email Impersonating a Cloud Storage Payment Failure (Source - Malwr-Analysis)
Phishing Email Impersonating a Cloud Storage Payment Failure (Source – Malwr-Analysis)

This approach marks a clear shift in attacker strategy, moving away from obviously suspicious domains and toward the deliberate exploitation of trusted cloud platforms that most email security tools simply do not flag by default.

How the Redirect Infrastructure Works

The entire mechanism depends on how Google Cloud Storage handles publicly accessible files. When an attacker creates a GCS bucket and uploads an HTML file to it, that file becomes reachable through a storage.googleapis.com URL — a domain that most email security gateways treat as legitimate.

Since these phishing emails also pass SPF and DKIM authentication checks, they rarely trigger spam filters or phishing warnings before reaching the recipient’s inbox.

The bucket “whilewait” acts as the attacker’s staging point within a Google Cloud project. The file comessuccess.html inside it is not a standard landing page — it is a script-heavy redirector that transfers the victim’s browser to an external malicious site almost instantly.

The victim sees nothing suspicious, because the entire transition completes in less than a second, well before they realize they have left Google’s infrastructure entirely.

Once on the malicious destination, victims are presented with what looks like a routine charge — typically a small shipping fee or service renewal tied to the lure from the original email.

This is the credit card harvesting stage. Any payment details entered on these pages are captured directly by the attackers, resulting in immediate and serious financial theft.

The chain is convincing precisely because the very first link appears to originate from Google, which makes it far harder for ordinary users to detect the threat in time.

Anyone who receives an email containing a link that starts with storage.googleapis.com should understand that it is not a direct communication from Google — it is a file hosted by a third party using Google’s infrastructure.

Users should always verify the sender’s email address carefully, as the phishing emails in this campaign consistently use randomized alphanumeric strings in the “From” field, a very clear indicator of automated mass fraud.

Security teams are strongly encouraged to report active GCS buckets used in phishing to the Google Cloud Abuse Team.

Since all 25-plus emails in this campaign rely on a single shared bucket, one successful takedown report targeting the “whilewait” bucket could shut down the entire phishing network at once.

End users should treat any unsolicited email that urges immediate action around storage, subscriptions, or prizes with healthy skepticism, regardless of how familiar the link appears.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta
Tushar Subhra Dutta
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Cyber Security Guide

Latest Cyber News

Expert Talks