Threat reportPhishingTL-2026-0033

Google Slides Presentation Abuse for Phishing and Malware Delivery

mediumACTIVE

Google Slides Presentation Abuse for Phishing and Malware (TL-2026-0033), also tracked as Google Docs Phishing, is a medium-severity phishing campaign scored CVSS 6.5, first published 2026-02-03. It has no confirmed attribution, affects N/A All Organizations, maps to 17 MITRE ATT&CK techniques (T1036, T1056, T1098), and is covered by 6 detection rules and 22 indicators of compromise.

CVSS
6.5/10Medium
CVEs
0None referenced
Techniques
17MITRE ATT&CK
Actors
0Not attributed
Detection rules
6SPL · KQL · Sigma
IOCs
22Indicators of compromise

Key facts for TL-2026-0033

Threat ID
TL-2026-0033
Also known as
Google Docs Phishing, Google Slides Abuse, Trusted Domain Phishing
Severity
MEDIUM
CVSS
6.5 (N/A - Technique)
Status
ACTIVE
Category
PHISHING
First published
Last reviewed
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
All Sectors, Finance, Healthcare, Education, Government, Technology
Target regions
Global
Detection rules
6
Indicators of compromise
22

How Google Slides Presentation Abuse for Phishing and Malware works

A widespread phishing campaign abuses Google Slides and the broader Google Workspace collaboration features to deliver credential harvesting attacks that bypass Secure Email Gateways (SEGs) and traditional email security controls. Attackers exploit Google Slides' comment/mention notification system, link embedding, and the inherent trust of google.com domains to deliver phishing emails that originate from legitimate Google infrastructure (noreply@google.com), pass SPF/DKIM/DMARC authentication, and redirect victims to credential harvesting pages. The campaign weaponizes multiple Google Workspace features: (1) Comment mention abuse — adding @victim to a Google Slides comment triggers a legitimate notification email from Google containing attacker-controlled text and links; (2) Google Slides as phishing page host — embedding credential forms or convincing 'click here' buttons within slides hosted on docs.google.com; (3) Link redirect chains — using Google Slides links that redirect through multiple Google services before landing on an attacker-controlled phishing domain; (4) Google Apps Script abuse — deploying malicious scripts that present fake OAuth consent screens or credential forms. This represents a broader class of 'trusted infrastructure abuse' where attackers weaponize legitimate SaaS platforms to evade security controls, exploiting the fundamental assumption that emails from Google are safe.

Google Slides phishing campaigns exploit the intersection of collaboration features and email security trust models.

**Attack Vector 1: Comment Mention Abuse**

The most prevalent technique exploits Google Slides' comment notification system: 1. Attacker creates a Google Slides presentation (free Google account or compromised Workspace account) 2. Attacker adds a comment mentioning the target by email: '@victim@company.com' 3. Google automatically sends an email notification from noreply@google.com 4. The email contains the comment text — which the attacker controls — including malicious links 5. The notification passes all email authentication (SPF, DKIM, DMARC) because it genuinely originates from Google 6. SEGs and email security tools see a legitimate Google notification and allow it through

This technique was first widely documented by Avanan (Check Point) in late 2021 when researchers observed a massive campaign using Google Docs/Slides comments to deliver phishing links to over 500 inboxes across 30+ organizations in a two-week period. The campaign evolved to include Google Slides specifically because the comment notification emails display the presentation title (controllable by attacker) and the comment text (containing malicious links) prominently.

**Attack Vector 2: Google Slides as Phishing Host**

Attackers create convincing Google Slides presentations that mimic: - Microsoft 365 login pages - Corporate SSO portals - DocuSign/Adobe Sign document signing pages - SharePoint file sharing notifications - Invoice/payment authorization screens

The slide contains a single image or text element with a hyperlinked button ('View Document', 'Sign In', 'Authorize Payment') that redirects to an external credential harvesting page. Because the initial URL is docs.google.com, it bypasses URL reputation checks.

**Attack Vector 3: Multi-Stage Redirect Chain**

More sophisticated campaigns use Google Slides as one stage in a multi-hop redirect: 1. Email with Google Slides link (trusted domain) 2. Slide redirects to Google Apps Script URL (script.google.com — also trusted) 3. Apps Script redirects to attacker phishing page with URL obfuscation 4. Phishing page harvests credentials, then redirects to legitimate service

Each hop uses a google.com domain, defeating URL scanning that checks the first-hop destination.

**Attack Vector 4: Google Workspace Notification Abuse (Extended)**

Beyond Slides comments, attackers abuse: - Google Docs comment mentions (same technique, Docs context) - Google Forms submission confirmations (embedded links in form descriptions) - Google Calendar event invitations (links in event descriptions) - Google Chat/Spaces messages (direct message with phishing link) - Google Drive sharing notifications (share document containing phishing link)

This creates a multi-channel phishing platform entirely within Google's ecosystem.

**Campaign Scale and Impact:**

- Avanan reported 100+ organizations targeted in a single campaign wave - Cofense Intelligence documented Google Workspace comment abuse bypassing Proofpoint, Mimecast, and Microsoft Defender SEGs - Abnormal Security identified campaigns using AI-generated slide content for more convincing social engineering - Campaigns observed targeting financial services, healthcare, education, and government sectors - Credential harvesting success rates estimated 3-5x higher than traditional phishing due to Google domain trust - Compromised accounts used for BEC (Business Email Compromise) follow-on attacks

**Why This Works:**

The fundamental security assumption being exploited: 'Emails from google.com are legitimate.' Email security has been built around sender reputation, domain authentication, and URL reputation. When the sender IS Google, the authentication IS valid, and the URLs ARE google.com — every traditional control fails. This is the same class of attack as Azure/SharePoint phishing (TL-0010) but using Google's infrastructure instead of Microsoft's.

**Google's Response:**

Google has implemented partial mitigations: - Rate limiting on comment mentions to external users - Warning banners on Google Docs/Slides when content contains suspicious links - Google Safe Browsing integration within Google Slides link clicks - Limited the ability to include clickable URLs in comment notification emails (partially)

However, attackers continuously adapt — using URL shorteners, Google redirect services (google.com/url?), and legitimate-looking domains to circumvent these controls.

MITRE ATT&CK techniques used in TL-2026-0033

defense-evasion

T1036 Masquerading

collection

T1056 Input Capture; T1114 Email Collection; T1530 Data from Cloud Storage

persistence

T1098 Account Manipulation

initial-access

T1199 Trusted Relationship; T1566 Phishing

execution

T1204 User Execution

credential-access

T1528 Steal Application Access Token; T1539 Steal Web Session Cookie

resource-development

T1583 Acquire Infrastructure; T1586 Compromise Accounts; T1608 Stage Capabilities

reconnaissance

T1589 Gather Victim Identity Information; T1591 Gather Victim Org Information

impact

T1657 Financial Theft

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Google Slides Presentation Abuse for Phishing and Malware

  • N/A — All Organizations
    Vulnerable versions: All users of email and web

Remediation for Google Slides Presentation Abuse for Phishing and Malware

Immediate actions

  • Implement URL inspection for Google Workspace links in email
  • Alert on clicks to Google Docs from external email sources
  • Train users to verify document legitimacy before clicking links
  • Block known malicious Google Docs IDs if identified

Workarounds

  • Require users to navigate to Google Drive directly rather than clicking email links
  • Implement web proxy rules to log all Google Docs access
  • Use browser extensions that warn on redirect chains

Longer-term hardening

  • Deploy browser isolation for external document links
  • Implement CASB to inspect Google Workspace traffic
  • Use advanced email security with safe links/attachments
  • Regular phishing awareness training including trusted domain abuse

Weaknesses (CWE) in Google Slides Presentation Abuse for Phishing and Malware

CWE-451

Timeline of Google Slides Presentation Abuse for Phishing and Malware

  • KrebsOnSecurity documents malicious Office 365 apps used in phishing — establishing the 'trusted platform abuse' pattern where SaaS collaboration features are weaponized for credential theft. OAuth consent phishing provides persistent, password-free access. Source: https://krebsonsecurity.com/2021/05/malicious-office-365-apps-are-the-ultimate-insiders/
  • Avanan (Check Point) publishes research on hackers exploiting Google Docs comment feature for phishing. Campaign targets 500+ inboxes across 30+ organizations in two weeks. Emails from noreply@google.com bypass all SEGs. Comment mentions deliver attacker-controlled text with malicious links. Source: https://www.avanan.com/blog/hackers-exploiting-google-docs-comment-feature
  • Cofense Intelligence documents Google Workspace comment exploitation bypassing Proofpoint, Mimecast, and Microsoft Defender SEGs. Attackers evolve to use Google Slides specifically for richer visual phishing lures. Multi-stage redirect chains through google.com domains. Campaign spreads to Google Forms and Calendar abuse.
  • CISA publishes comprehensive phishing guidance (AA23-291A) addressing trusted platform abuse. Recommends phishing-resistant MFA, user reporting programs, and post-delivery URL scanning. Notes that sender reputation alone is insufficient when legitimate services are weaponized. Source: https://www.cisa.gov/resources-tools/resources/phishing-guidance-stopping-attack-cycle-phase-one
  • Security researchers document AI-generated Google Slides phishing content — attackers use LLMs to create more convincing presentation decks mimicking corporate branding, DocuSign templates, and invoice approvals. AI lowers the skill barrier and increases production volume of unique phishing slides.
  • BleepingComputer documents evolution of attachment-based phishing evasion using SVG files with embedded HTML/JavaScript. Demonstrates broader trend: attackers continuously find new formats and platforms that evade security scanning. Google Slides phishing is part of this pattern — using trusted platforms as evasion layers. Source: https://www.bleepingcomputer.com/news/security/phishing-emails-increasingly-use-svg-attachments-to-evade-detection/
  • As of 2026-05-29, this trusted-Google-infrastructure phishing technique (no CVE; CWE-451) remains actively exploited: a Dec 2025 campaign abused Google Cloud's Send Email feature to hit ~3,200 orgs from a noreply google.com address, bypassing SPF/DKIM/DMARC and SEGs (The Hacker News, Jan 2026). Google has rolled out only partial comment-spam mitigations for Docs/Slides, and the financially motivated activity is unattributed and ongoing, so it stays ACTIVE.

Sources cited for Google Slides Presentation Abuse for Phishing and Malware

Detection coverage for TL-2026-0033

As of 2026-02-03, Threadlinqs Intelligence publishes 6 detection rule(s) for TL-2026-0033 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

6 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
22 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats