Cybercriminals Use Firebase Developer Accounts to Distribute Phishing Emails
Scammers are leveraging free developer accounts on Google Firebase to send fraudulent emails that effectively bypass traditional security filters.
Google Firebase is a widely used platform for building mobile and web applications.
Cybercriminals are now registering these free accounts to host phishing content and send emails, as reported by PaloAlto Network.
Because the emails originate from subdomains ending in firebaseapp.com a domain associated with Google’s reputable infrastructure they possess a high domain reputation.
This allows the malicious emails to slip past spam blocklists and land directly in the victim’s primary inbox.
The campaign relies on two primary psychological triggers to manipulate victims: fear and greed.
The investigation highlighted specific patterns in the sender addresses.
These addresses often use random alphanumeric strings attached to the Firebase domain. Observed sender examples include:
noreply@pr01-1f199.firebaseapp[.]comnoreply@pro04-4a08a.firebaseapp[.]comnoreply@zamkksdjauys.firebaseapp[.]comOnce a user clicks the call-to-action button in the email, they are redirected through various URL shorteners or compromised sites to the final phishing page. Malicious redirect chains have been observed using URLs such as:
hxxps[:]//rebrand[.]ly/auj0nghhxxp[:]//clouud.thebatata[.]org/click[.]php?hxxps[:]//www.servercrowdmanage[.]com/5N98X9F/21NRJNSZ/This campaign demonstrates how attackers are “living off the land” by using trusted services to hide malicious activity.
Security teams are advised to closely monitor traffic from firebaseapp.com subdomains that do not align with known business applications.
Users should remain vigilant against unsolicited emails demanding urgent action, even if the technical sender address appears to be hosted on a legitimate platform.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.
The post Cybercriminals Use Firebase Developer Accounts to Distribute Phishing Emails appeared first on Cyber Security News.
Canva introduced a new feature that separates flat image files and AI-generated visuals into layered,…
Datadog has announced it is to launch a UK datacentre presence. Demand for local datacentres…
At ZohoDay 2026, I sat down with Anand Nergunam Suryanarayanan, Vice President of Revenue Acceleration,…
Jitterbit has published new data via its 2026 AI Automation Benchmark Report. Jitterbit supports accelerating…
Tricentis has launched its unified, agentic software quality platform supported by the new Tricentis AI…
Platform engineering is getting squeezed from both sides. On one side, developers have rapidly embraced…
This website uses cookies.