Skip to content
Threat Feed

Tag

Google-Workspace

10 briefs RSS
high threat

Operation Fake KickOff: Attackers Abuse Recruiters and SaaS to Harvest Work Credentials

O-UNC-038 is conducting a multi-stage Adversary-in-the-Middle (AiTM) phishing operation that abuses legitimate SaaS platforms and recruiter identities to steal corporate Google Workspace credentials and bypass multi-factor authentication.

Google Workspace O-UNC-038 phishing credential-theft aitm social-engineering mfa-bypass saas-abuse google-workspace
2r 9t 1i
medium advisory

Google Workspace Custom Admin Role Created for Persistence

Adversaries may create custom administrative roles in Google Workspace to establish persistence with tailored, elevated permissions, which are then assigned to compromised or attacker-controlled accounts to bypass security controls, grant OAuth access, or modify mail routing.

Google Workspace google-workspace cloud-security persistence privilege-escalation iam
1r 2t
high advisory

Google Workspace Admin Role Assigned to a User or Group

Adversaries leverage the assignment of administrative roles within Google Workspace to an existing or new user/group, establishing persistence and escalating privileges to gain broad control over the tenant, including bypassing single sign-on.

Google Workspace cloud-security google-workspace persistence privilege-escalation account-manipulation saas-security
2r 2t
medium advisory

Google Workspace Admin Role Deletion

Adversaries with elevated privileges within Google Workspace may delete custom administrative roles to impede security operations, remove delegated administrator access, or obfuscate their activities during an active incident, leading to disrupted delegated administration, loss of security team access, or hindrance of incident response efforts.

Google Workspace cloud google-workspace identity-and-access-audit impact defense-evasion admin-role-deletion
2r 2t
high advisory

Google Workspace Device Registration After OAuth from Suspicious ASN

Detects a sequence of events in Google Workspace where OAuth authorization from a suspicious ASN is immediately followed by device registration, potentially indicating attacker-controlled device enrollment after user authorization of a sensitive client, possibly related to Tycoon2FA.

Google Workspace cloud google-workspace persistence initial-access tycoon2fa
2r 2t
medium advisory

Google Workspace Object Copied from External Drive Followed by OAuth Consent

Detects a sequence of events where a user copies a Google Workspace object (spreadsheet, form, document, or script) from an external drive and subsequently grants OAuth permissions to a custom application, potentially indicating a phishing attack leveraging container-bound scripts.

Google Workspace +5 google-workspace oauth phishing initial-access persistence
1r 3t
medium advisory

Google Drive Ownership Transferred via Google Workspace

Adversaries may transfer files to an adversary account for potential exfiltration by abusing Google Workspace administration permissions to transfer file ownership within Google Drive.

Google Drive +2 google-workspace data-exfiltration cloud
2r 2t
medium advisory

Google Workspace MFA Enforcement Disabled

Detection of multi-factor authentication (MFA) enforcement being disabled for Google Workspace users, potentially weakening security controls and leading to account compromise.

Google Workspace google-workspace mfa account-compromise
2r 3t
high advisory

Google Workspace Drive Encryption Key Accessed by Anonymous User

An external (anonymous) user has viewed, copied, or downloaded an encryption key file from a Google Workspace drive, potentially leading to unauthorized access to sensitive data or authentication on behalf of users via rogue access links.

Google Workspace Drive google-workspace credential-access data-exfiltration
2r 2t
medium advisory

Google Workspace 2SV Policy Disabled

An adversary may disable 2-Step Verification (2SV) in Google Workspace to weaken account security and facilitate unauthorized access.

Google Workspace google-workspace 2sv persistence
2r 1t