Hackers Weaponise Google Appsheet To Bypass Email Defences - Arabian Post
The cybersecurity community is confronting a highly evolved phishing campaign that exploits Google's no-code AppSheet platform to harvest credentials and two-factor authentication codes. Attackers are sending authentic-looking emails from the legitimate domain noreply@appsheet. com-circumventing common defences such as SPF, DKIM and DMARC-and impersonating Meta to pressure users into submitting sensitive data. On 20 April 2025, AppSheet-originated emails made up 10.88 percent of all phishing attempts intercepted by KnowBe4 Defend, with 98 percent mimicking Meta and the remainder posing as PayPal.
These counterfeit communications are crafted with precise Meta branding and dramatise account deletion threats, deploying a 24-hour deadline and unique“Case ID” polymorphic identifiers, making each email distinct and harder to flag through static detection rules. Clicking the embedded“Submit an Appeal” link takes recipients to a convincing phishing page hosted on Vercel, complete with animated logos and a mirrored Meta interface. Users are prompted to enter their credentials and 2FA codes twice under the false pretext of an error, a tactic that simultaneously increases data accuracy and induces confusion.
The phishing site functions as a man-in-the-middle proxy, relaying credentials and 2FA codes in real time to Meta. This allows attackers to hijack sessions and bypass multi-factor authentication entirely.
“Weaponise Google AppSheet” thus captures this attack's essence: abuse of a trusted, legitimate development tool to deliver phishing at scale, bypassing conventional defences and enabling sophisticated session compromise.
This campaign typifies a growing threat trend: exploitation of trusted cloud and workflow platforms-such as Microsoft, Google Forms, QuickBooks and Telegram-to evade security filters and manipulate user trust. Traditional email gateways, including Microsoft 365 defences, struggle to counteract these nuanced threats.
See also Harvard Dropouts Set to Launch AI Glasses That Record ConversationsIn response, organisations are increasingly turning to integrated, AI-powered email security tools that assess message intent over sender legitimacy. Platforms like KnowBe4 Defend, which incorporates threat awareness training and real-time email analysis, are being adopted alongside simulated phishing exercises that educate users about real attacks.
Notice an issue? Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com . We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity. Legal Disclaimer:
MENAFN provides the
information “as is” without warranty of any kind. We do not accept
any responsibility or liability for the accuracy, content, images,
videos, licenses, completeness, legality, or reliability of the information
contained in this article. If you have any complaints or copyright
issues related to this article, kindly contact the provider above.
Most popular stories
Market Research

- Japan Buy Now Pay Later Market Size To Surpass USD 145.5 Billion By 2033 CAGR Of 22.23%
- BTCC Summer Festival 2025 Unites Japan's Web3 Community
- GCL Subsidiary, 2Game Digital, Partners With Kucoin Pay To Accept Secure Crypto Payments In Real Time
- Smart Indoor Gardens Market Growth: Size, Trends, And Forecast 20252033
- Nutritional Bar Market Size To Expand At A CAGR Of 3.5% During 2025-2033
- Pluscapital Advisor Empowers Traders To Master Global Markets Around The Clock
Comments
No comment