# Google Slides Presentation Abuse for Phishing and Malware Delivery

> A widespread phishing campaign abuses Google Slides and the broader Google Workspace collaboration features to deliver credential harvesting attacks that bypass Secure Email Gateways (SEGs) and traditional email security controls. Attackers exploit Google Slides' comment/mention notification system, link embedding, and the inherent trust of google.com domains to deliver phishing emails that originate from legitimate Google infrastructure (noreply@google.com), pass SPF/DKIM/DMARC authentication, and redirect victims to credential harvesting pages. The campaign weaponizes multiple Google Workspace features: (1) Comment mention abuse — adding @victim to a Google Slides comment triggers a legitimate notification email from Google containing attacker-controlled text and links; (2) Google Slides as phishing page host — embedding credential forms or convincing 'click here' buttons within slides hosted on docs.google.com; (3) Link redirect chains — using Google Slides links that redirect through multiple Google services before landing on an attacker-controlled phishing domain; (4) Google Apps Script abuse — deploying malicious scripts that present fake OAuth consent screens or credential forms. This represents a broader class of 'trusted infrastructure abuse' where attackers weaponize legitimate SaaS platforms to evade security controls, exploiting the fundamental assumption that emails from Google are safe.

- **Published:** 2026-02-03T00:26:00Z
- **Last reviewed:** 2026-02-03T00:26:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0033
- **ID:** TL-2026-0033
- **Severity:** MEDIUM (CVSS 6.5)
- **Category:** PHISHING
- **Status:** ACTIVE
- **Detections:** 6 · **IOCs:** 22 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Google Slides phishing campaigns exploit the intersection of collaboration features and email security trust models.

**Attack Vector 1: Comment Mention Abuse**

The most prevalent technique exploits Google Slides' comment notification system:
1. Attacker creates a Google Slides presentation (free Google account or compromised Workspace account)
2. Attacker adds a comment mentioning the target by email: '@victim@company.com'
3. Google automatically sends an email notification from noreply@google.com
4. The email contains the comment text — which the attacker controls — including malicious links
5. The notification passes all email authentication (SPF, DKIM, DMARC) because it genuinely originates from Google
6. SEGs and email security tools see a legitimate Google notification and allow it through

This technique was first widely documented by Avanan (Check Point) in late 2021 when researchers observed a massive campaign using Google Docs/Slides comments to deliver phishing links to over 500 inboxes across 30+ organizations in a two-week period. The campaign evolved to include Google Slides specifically because the comment notification emails display the presentation title (controllable by attacker) and the comment text (containing malicious links) prominently.

**Attack Vector 2: Google Slides as Phishing Host**

Attackers create convincing Google Slides presentations that mimic:
- Microsoft 365 login pages
- Corporate SSO portals
- DocuSign/Adobe Sign document signing pages
- SharePoint file sharing notifications
- Invoice/payment authorization screens

The slide contains a single image or text element with a hyperlinked button ('View Document', 'Sign In', 'Authorize Payment') that redirects to an external credential harvesting page. Because the initial URL is docs.google.com, it bypasses URL reputation checks.

**Attack Vector 3: Multi-Stage Redirect Chain**

More sophisticated campaigns use Google Slides as one stage in a multi-hop redirect:
1. Email with Google Slides link (trusted domain)
2. Slide redirects to Google Apps Script URL (script.google.com — also trusted)
3. Apps Script redirects to attacker phishing page with URL obfuscation
4. Phishing page harvests credentials, then redirects to legitimate service

Each hop uses a google.com domain, defeating URL scanning that checks the first-hop destination.

**Attack Vector 4: Google Workspace Notification Abuse (Extended)**

Beyond Slides comments, attackers abuse:
- Google Docs comment mentions (same technique, Docs context)
- Google Forms submission confirmations (embedded links in form descriptions)
- Google Calendar event invitations (links in event descriptions)
- Google Chat/Spaces messages (direct message with phishing link)
- Google Drive sharing notifications (share document containing phishing link)

This creates a multi-channel phishing platform entirely within Google's ecosystem.

**Campaign Scale and Impact:**

- Avanan reported 100+ organizations targeted in a single campaign wave
- Cofense Intelligence documented Google Workspace comment abuse bypassing Proofpoint, Mimecast, and Microsoft Defender SEGs
- Abnormal Security identified campaigns using AI-generated slide content for more convincing social engineering
- Campaigns observed targeting financial services, healthcare, education, and government sectors
- Credential harvesting success rates estimated 3-5x higher than traditional phishing due to Google domain trust
- Compromised accounts used for BEC (Business Email Compromise) follow-on attacks

**Why This Works:**

The fundamental security assumption being exploited: 'Emails from google.com are legitimate.' Email security has been built around sender reputation, domain authentication, and URL reputation. When the sender IS Google, the authentication IS valid, and the URLs ARE google.com — every traditional control fails. This is the same class of attack as Azure/SharePoint phishing (TL-0010) but using Google's infrastructure instead of Microsoft's.

**Google's Response:**

Google has implemented partial mitigations:
- Rate limiting on comment mentions to external users
- Warning banners on Google Docs/Slides when content contains suspicious links
- Google Safe Browsing integration within Google Slides link clicks
- Limited the ability to include clickable URLs in comment notification emails (partially)

However, attackers continuously adapt — using URL shorteners, Google redirect services (google.com/url?), and legitimate-looking domains to circumvent these controls.

## MITRE ATT&CK

- T1589 Gather Victim Identity Information
- T1591 Gather Victim Org Information
- T1583 Acquire Infrastructure
- T1608 Stage Capabilities
- T1586 Compromise Accounts
- T1566 Phishing
- T1199 Trusted Relationship
- T1204 User Execution
- T1098 Account Manipulation
- T1036 Masquerading
- T1685 Disable or Modify Tools
- T1056 Input Capture
- T1528 Steal Application Access Token
- T1539 Steal Web Session Cookie
- T1530 Data from Cloud Storage
- T1114 Email Collection
- T1657 Financial Theft

## Sources

- [Avanan — Hackers Exploiting Google Docs Comment Feature for Phishing](https://www.avanan.com/blog/hackers-exploiting-google-docs-comment-feature)
- [BleepingComputer — SVG Phishing Evasion Techniques](https://www.bleepingcomputer.com/news/security/phishing-emails-increasingly-use-svg-attachments-to-evade-detection/)
- [Cofense Intelligence — Google Workspace Comment Exploitation](https://cofense.com/blog/google-workspace-exploitation)
- [KrebsOnSecurity — Malicious Office 365 Apps](https://krebsonsecurity.com/2021/05/malicious-office-365-apps-are-the-ultimate-insiders/)
- [CISA — Phishing Guidance: Stopping the Attack Cycle at Phase One](https://www.cisa.gov/resources-tools/resources/phishing-guidance-stopping-attack-cycle-phase-one)
- [Google Workspace Admin — Protect Against Phishing](https://support.google.com/a/answer/9157861)
- [Abnormal Security — Google Services Abuse in Phishing](https://abnormalsecurity.com/blog/google-services-abuse-phishing)
- [Proofpoint — Cloud Account Compromise Trends](https://www.proofpoint.com/us/blog/cloud-security/cloud-account-compromise)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0033
