Google Tasks Feature Exploited in New Sophisticated Phishing Campaign
In December 2025, over 3,000 organizations, primarily within the manufacturing sector, were targeted by an advanced phishing campaign. This operation utilized Google's application infrastructure to circumvent enterprise email security mechanisms.
In December 2025, over 3,000 organizations, primarily within the manufacturing sector, were targeted by an advanced phishing campaign. This operation utilized Google's application infrastructure to circumvent enterprise email security mechanisms.
The attackers dispatched fraudulent emails from legitimate Google systems, marking a notable evolution in how threat actors exploit credible platforms. Unlike conventional phishing tactics that depend on domain spoofing or compromised servers, this campaign fully operated within Google's legitimate systems.
The emails successfully cleared all standard authentication checks, including SPF, DKIM, DMARC, and CompAuth, posing a significant challenge for conventional email security tools.
The phishing emails masqueraded as authentic Google Tasks notifications, purporting to be internal task assignments requiring employee verification. Recipients were encouraged to interact with prompts such as "View task" or "Mark complete," which redirected them to a malicious page hosted on Google Cloud Storage.
The attack exploited three critical vulnerabilities in traditional security frameworks:
In December 2025, over 3,000 organizations, primarily within the manufacturing sector, were targeted by an advanced phishing campaign.
Trusted Sender Infrastructure: Emails originated from valid Google systems, benefiting from Google's high sender reputation and widespread organizational allowlisting. High-Fidelity Brand Impersonation: The emails closely mimicked Google Tasks UI, branding, and familiar notification elements, making them visually indistinguishable from legitimate communications. Payload on Trusted Domains: The malicious content was hosted on Google Cloud Storage URLs, nullifying the effectiveness of URL reputation-based detection methods.
Email security systems, which typically rely on sender reputation, domain trust, and authentication verification, were unable to detect these emails as all elements appeared legitimate. The misuse of Google Tasks for HR verifications or workflow triggers that redirected to Cloud Storage went unnoticed by traditional tools.
Security researchers at RavenMail identified the campaign by analyzing the context and intent rather than relying solely on sender credentials. They noted discrepancies such as internal tasks emanating from external Google addresses and Cloud Storage endpoints that were incompatible with legitimate Google Tasks operations.
This campaign is part of an increasing trend where attackers misuse Google's cloud services, including AppSheet, Google Forms, and Application Integration, as phishing delivery mechanisms. The threat is not limited to Google; any trusted SaaS platform with email-sending capabilities could be exploited.
Organizations need to transition from trust-based email security models to intent-centric detection systems that evaluate workflow legitimacy and contextual appropriateness, irrespective of sender reputation.
Based on reporting by GBHackers.
