A new cybersecurity report has put an unexpected Google service in the spotlight. TraceX Labs says Google Apps Script Web Apps are being used as part of online campaigns involving phishing, fraud, malware distribution, search spam and malicious redirects.
Google Apps Script is normally associated with automation and productivity. Developers use it to connect Google services, build simple web applications and automate repetitive tasks. The technology itself is legitimate, but researchers say its features can also be incorporated into abuse campaigns.
The findings were published by TraceX Labs on September 30, 2026, in a report identified as GLOBAL-026.
From a normal Google link to a suspicious campaign
One reason these cases can be difficult to investigate is that a suspicious campaign may not begin with an obviously malicious website.
According to the report, an Apps Script Web App can appear somewhere in the journey before a visitor reaches another destination. A person could encounter such a link through a search engine, social media, email or a messaging service.
The Apps Script URL may then process a request, display content or redirect the visitor elsewhere.
That does not mean the Google service itself is responsible for the activity. TraceX Labs specifically distinguishes between the legitimate platform and the way third parties may use it.
Phishing is one of the areas being investigated
The report looks at several types of scams that can involve intermediary web pages.
These include attempts to collect login credentials, investment-related scams, employment scams, fake payment activity and other forms of social engineering.
In such cases, looking only at the first URL may not reveal the full picture. Investigators may need to follow the chain to determine the final destination and identify other infrastructure involved in the campaign.
TraceX Labs also refers to cases involving Android APK downloads and possible malware distribution. The researchers caution that malware-related conclusions should be supported by technical analysis or trustworthy reputation information.
Search results can also become part of the problem
The report gives considerable attention to SEO manipulation.
Some suspicious campaigns may use large amounts of automatically generated or keyword-focused content to attract traffic from search engines. Other signs can include doorway pages, duplicated page structures, excessive outbound links and unusual redirect patterns.
TraceX Labs says some activity of this type could potentially fall under SEO Poisoning, listed as T1608.006 in the MITRE ATT&CK framework.
Still, the researchers warn against treating individual SEO signals as proof of malicious activity. Context and supporting evidence remain important.
Not every unusual page is a cyberattack
This is one of the more important distinctions in the report.
A page containing terms associated with gambling, drugs, adult content or piracy does not automatically prove that the operator is conducting a criminal campaign.
TraceX Labs discusses several categories of spam, including betting and gambling content, adult or NSFW spam, drug-related spam, synthetic-media and deepfake spam, video and search spam, and movie-piracy-related activity.
But the presence of these topics alone is not considered sufficient evidence for classification.
Researchers are encouraged to look at the broader behaviour of the infrastructure.
A separate section covers suspected CSAM-related activity
The report also includes a section dealing with suspected CSAM/CSE-related infrastructure.
TraceX Labs marks this area as “Suspected / Corroboration Required.” In other words, the researchers say further evidence is necessary before treating the finding as established.
The report also stresses responsible handling of evidence and advises investigators not to unnecessarily download, reproduce or redistribute suspected illegal material.
Why a Google domain should not be treated as a security guarantee
The research highlights a common challenge for security teams investigating cloud infrastructure.
Seeing a Google-owned URL does not necessarily tell investigators who created the content or what happens after the URL is opened. A linked website may be operated by an unrelated party, while the cloud service may simply be one component in the overall chain.
The same applies to HTTPS. An encrypted connection protects data in transit, but HTTPS by itself does not establish that the website is trustworthy.
For this reason, TraceX Labs recommends looking beyond the domain name.
Following the evidence can reveal more
Security teams investigating suspicious Apps Script activity can examine a number of technical indicators.
These may include unusual URL parameters, deployment identifiers, destination domains, IP addresses, ASNs, certificates and file hashes.
Network logs can also be useful. Proxy records may reveal where a user was redirected and whether files were downloaded during the session.
On individual devices, security teams can look for indicators such as unexpected APK downloads, suspicious file execution and unusual browser-based downloads or credential submissions.
TraceX Labs recommends a step-by-step investigation
Rather than automatically blocking Apps Script URLs, the report recommends a structured approach to investigation:
Discover → Validate → Correlate → Classify → Report
The idea is to establish what has actually been observed, verify the available evidence and connect it with other infrastructure before assigning a classification.
TraceX Labs uses categories including Observed, Correlated, Suspected, Potential, Benign and Unknown.
The researchers also caution that a single URL, screenshot or technical indicator should not automatically be used to establish ownership, criminal intent or an association with Google.
The bigger issue is the misuse of trusted infrastructure
The report ultimately points to a broader problem facing cybersecurity teams.
Attackers do not necessarily need to build every part of their infrastructure from scratch. Legitimate online services can sometimes become components in campaigns that involve malicious destinations, deceptive content or unwanted redirects.
That makes context increasingly important.
For security researchers, the challenge is not simply identifying whether an Apps Script URL exists. It is understanding what the URL is doing, where it leads, what content is being delivered and how it connects to the rest of the campaign.
TraceX Labs says its full report contains additional technical details and guidance for threat hunters, SOC teams, CERTs and other investigators examining suspicious web infrastructure.
Source: https://tracexlabs.com/reports/google-apps-script-abuse-threat-report-2026.html