Cybercriminals Use Firebase Developer Accounts to Distribute Phishing Emails
Scammers are leveraging free developer accounts on Google Firebase to send fraudulent emails that effectively bypass traditional security filters.
Google Firebase is a widely used platform for building mobile and web applications. It offers a “free tier” that allows developers to test code and host small projects without cost.
Cybercriminals are now registering these free accounts to host phishing content and send emails, as reported by PaloAlto Network.
Because the emails originate from subdomains ending in firebaseapp.com a domain associated with Google’s reputable infrastructure they possess a high domain reputation.
This allows the malicious emails to slip past spam blocklists and land directly in the victim’s primary inbox.
The campaign relies on two primary psychological triggers to manipulate victims: fear and greed.
The investigation highlighted specific patterns in the sender addresses.
These addresses often use random alphanumeric strings attached to the Firebase domain. Observed sender examples include:
noreply@pr01-1f199.firebaseapp[.]comnoreply@pro04-4a08a.firebaseapp[.]comnoreply@zamkksdjauys.firebaseapp[.]comOnce a user clicks the call-to-action button in the email, they are redirected through various URL shorteners or compromised sites to the final phishing page. Malicious redirect chains have been observed using URLs such as:
hxxps[:]//rebrand[.]ly/auj0nghhxxp[:]//clouud.thebatata[.]org/click[.]php?hxxps[:]//www.servercrowdmanage[.]com/5N98X9F/21NRJNSZ/This campaign demonstrates how attackers are “living off the land” by using trusted services to hide malicious activity.
Security teams are advised to closely monitor traffic from firebaseapp.com subdomains that do not align with known business applications.
Users should remain vigilant against unsolicited emails demanding urgent action, even if the technical sender address appears to be hosted on a legitimate platform.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.
The post Cybercriminals Use Firebase Developer Accounts to Distribute Phishing Emails appeared first on Cyber Security News.
I first got into reading romantasy books after a friend of mine recommended Fourth Wing…
IO Interactive has assured fans that there will be more Hitman adventures, and the team…
Diablo 4 fans have finally discovered the game's secret cow level, though some fans are…
INDIANAPOLIS, Ind. (WOWO) — A federal judge has cleared the way for a religious freedom…
INDIANAPOLIS, Ind. (WOWO) — The generosity of FOX59/CBS4 viewers will help provide thousands of meals…
American politician and diplomat Howard Baker (1925-2014), United States Senator from Tennessee, during the Select…
This website uses cookies.