<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Saas-Security - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/saas-security/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 18 Jun 2026 15:31:12 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/saas-security/feed.xml" rel="self" type="application/rss+xml"/><item><title>Google Workspace Admin Role Assigned to a User or Group</title><link>https://feed.craftedsignal.io/briefs/2026-06-google-workspace-admin-role-assigned/</link><pubDate>Thu, 18 Jun 2026 15:31:12 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-06-google-workspace-admin-role-assigned/</guid><description>Adversaries leverage the assignment of administrative roles within Google Workspace to an existing or new user/group, establishing persistence and escalating privileges to gain broad control over the tenant, including bypassing single sign-on.</description><content:encoded><![CDATA[<p>Adversaries are known to target cloud environments like Google Workspace to establish persistent access and escalate privileges. A critical technique involves assigning administrative roles, such as the <code>SUPER_ADMIN_ROLE</code> or other <code>*_ADMIN_ROLE</code> types, to existing or newly created user accounts or groups. This action, often occurring post-initial compromise, grants attackers broad control over the Google Workspace tenant, including the ability to manage users, devices, security settings, and applications. Such elevated privileges enable adversaries to bypass security mechanisms like Single Sign-On (SSO), ensure long-term presence, and facilitate follow-on activities like data exfiltration, modifying mail routing, or altering other critical configurations, posing a significant risk to organizational data and operations.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li><strong>Initial Compromise</strong>: Adversary obtains initial access to a Google Workspace account, potentially an administrator account or an account with privileges to create users or manage groups.</li>
<li><strong>Privilege Discovery</strong>: The adversary identifies existing user accounts or creates new ones that can be granted elevated administrative roles within Google Workspace.</li>
<li><strong>Role Assignment</strong>: The adversary assigns a high-privilege administrative role (e.g., <code>SUPER_ADMIN_ROLE</code>, <code>GROUP_ADMIN_ROLE</code>) to a compromised or newly created user account or an existing group.</li>
<li><strong>Persistence Establishment</strong>: The elevated role provides the adversary with sustained access to the Google Workspace environment, often bypassing standard security controls like Single Sign-On (SSO).</li>
<li><strong>Further Actions</strong>: Utilizing the newly acquired administrative privileges, the adversary performs additional malicious activities, such as creating OAuth tokens, modifying security controls, changing mail routing, or altering SSO settings.</li>
<li><strong>Data Exfiltration/Impact</strong>: The adversary may then proceed with data exfiltration, service disruption, or other objectives, maintaining broad control over the tenant's identity, device, and application settings.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The successful assignment of administrative roles to an adversary-controlled account grants comprehensive control over the affected Google Workspace tenant. This can lead to unauthorized access to sensitive organizational data, alteration of critical security controls (such as SSO settings), disruption of email communications, and creation of backdoors (e.g., OAuth tokens) for sustained access. Organizations across all sectors are vulnerable, and the impact can range from severe data breaches and compliance failures to operational paralysis and reputational damage.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Deploy the Sigma rules in this brief to your SIEM and tune for your environment, specifically focusing on <code>google_workspace.admin.role.name</code> values.</li>
<li>Ensure Google Workspace Admin logs are being ingested into your security monitoring platform to enable detection of <code>event.action: &quot;ASSIGN_ROLE&quot;</code> events.</li>
<li>Regularly audit existing administrative role assignments within Google Workspace, paying close attention to <code>*_ADMIN_ROLE</code> types.</li>
<li>Implement security best practices outlined by Google, available at <code>https://support.google.com/a/answer/7587183</code>.</li>
<li>Investigate <code>user.email</code> and <code>source.ip</code> for any user performing <code>ASSIGN_ROLE</code> actions that appear unusual.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>cloud-security</category><category>google-workspace</category><category>persistence</category><category>privilege-escalation</category><category>account-manipulation</category><category>saas-security</category></item></channel></rss>