भारत

TraceX Labs की रिपोर्ट में Google Apps Script के दुरुपयोग का खुलासा, Phishing से Malware और SEO Spam तक की जांच

Uma Verma
28 Sept 2026 12:24 AM IST
TraceX Labs की रिपोर्ट में Google Apps Script के दुरुपयोग का खुलासा, Phishing से Malware और SEO Spam तक की जांच
x
TraceX Labs की नई Threat Intelligence Report में Google Apps Script Web Apps के संभावित दुरुपयोग का विश्लेषण किया गया है। रिपोर्ट में Phishing, Online Fraud, Malware Distribution, SEO Manipulation, Spam, Malicious Redirection, Deepfake, NCII और संदिग्ध CSAM/CSE-related Infrastructure जैसे मामलों की जांच की गई है।

साइबर सुरक्षा क्षेत्र में काम करने वाली कंपनी TraceX Labs ने Google Apps Script Web Apps के संभावित दुरुपयोग को लेकर एक नई Threat Intelligence Report जारी की है। रिपोर्ट में Phishing, Online Fraud, Malware Distribution, SEO Manipulation, Spam और Malicious Redirection जैसी गतिविधियों का विश्लेषण किया गया है। इसके अलावा NCII, Sextortion, Deepfake और संदिग्ध CSAM/CSE-संबंधित Infrastructure जैसे संवेदनशील मामलों को भी रिपोर्ट में शामिल किया गया है।

30 सितंबर 2026 को जारी इस रिपोर्ट का शीर्षक “Abuse of Google Apps Script Web Apps for Phishing, Fraud, Malware Distribution, SEO Manipulation, Spam, CSAM/CSE-Related Abuse and Malicious Redirection” है। रिपोर्ट को GLOBAL-026 पहचान संख्या दी गई है और इसमें Threat Assessment को High बताया गया है।

Google Apps Script क्या है?

Google Apps Script Google का एक वैध Cloud-based Platform है। इसका इस्तेमाल Web Applications बनाने, Automation करने और Google की विभिन्न Services को आपस में जोड़ने के लिए किया जाता है।

इसके Web Apps HTTP Requests को Process करने, Parameters स्वीकार करने, HTML Pages तैयार करने और External Resources के साथ Communication करने में सक्षम होते हैं।

TraceX Labs की रिपोर्ट का उद्देश्य Google Apps Script को Malicious Platform बताना नहीं है। रिपोर्ट में यह जांच की गई है कि इसकी वैध सुविधाओं का कुछ मामलों में Third-Party Abuse के लिए किस तरह इस्तेमाल किया जा सकता है।

किसी User को Search Engine, Email, Social Media या Messaging Platform के जरिए Apps Script URL भेजा जा सकता है। यह URL आगे किसी Landing Page, External Website या दूसरे Resource पर Redirect कर सकता है।

Phishing और Online Fraud

रिपोर्ट में Phishing और Online Fraud से संबंधित विभिन्न गतिविधियों का अध्ययन किया गया है। इनमें Credential Harvesting, Investment Scam, Employment Scam, Fake Payment Pages, Impersonation और Social Engineering जैसी गतिविधियां शामिल हैं।

ऐसे मामलों में Apps Script Web App Landing Page, Intermediate Page या Redirector की भूमिका निभा सकता है। इसके बाद User को किसी External Infrastructure पर भेजा जा सकता है।

TraceX Labs ने Malicious Android APK Distribution और Malware Delivery से संबंधित मामलों का भी अध्ययन किया है। हालांकि रिपोर्ट में यह स्पष्ट किया गया है कि केवल Google Apps Script URL से जुड़ा होना किसी File या Website को Malware साबित नहीं करता। इसके लिए Technical Analysis और विश्वसनीय Reputation Information जैसी अतिरिक्त जानकारी आवश्यक है।

SEO Manipulation और Search Spam

रिपोर्ट का एक महत्वपूर्ण हिस्सा Search Engine Manipulation से संबंधित है।

TraceX Labs ने Keyword-heavy Pages, Doorway Pages, Automatically Generated Content, Repeated Templates, Unrelated Keywords, बड़ी संख्या में Outbound Links और Redirect Chains जैसे संकेतों को Investigation के दौरान महत्वपूर्ण बताया है।

यदि किसी Infrastructure का इस्तेमाल जानबूझकर Search Visibility को Manipulate करने के लिए किया जा रहा हो, तो यह MITRE ATT&CK T1608.006 – SEO Poisoning से संबंधित हो सकता है।

रिपोर्ट में Backlink Manipulation और Google Search तथा Video Search से जुड़े Spam को भी शामिल किया गया है।

Malware और Android APK Distribution

Google Apps Script से जुड़े Infrastructure के जरिए Malware या Malicious Android APK Distribution भी रिपोर्ट के अध्ययन का हिस्सा है।

TraceX Labs के अनुसार ऐसी गतिविधियों की जांच करते समय केवल शुरुआती Apps Script URL को देखना पर्याप्त नहीं है। Security Analysts को Redirect Destination, Downloaded File, File Hash, Endpoint Activity और संबंधित Infrastructure की भी जांच करनी चाहिए।

इससे यह पता लगाने में मदद मिल सकती है कि Apps Script URL केवल एक Intermediate Layer है या किसी बड़े Campaign के दूसरे Components से भी जुड़ा हुआ है।

Spam, Gambling और Drug-related Campaigns

रिपोर्ट में अलग-अलग प्रकार के Spam और Abuse को भी शामिल किया गया है। इनमें Gambling और Betting Spam, Adult और NSFW Spam, Drug-related Spam, Deepfake और Synthetic Media Spam, Google Video और Search Spam तथा Movie Piracy-related Search Activity शामिल हैं।

TraceX Labs ने यह भी स्पष्ट किया है कि किसी Page पर Gambling, Drugs या Piracy से संबंधित Keywords मिलना अपने आप में Cybercrime का प्रमाण नहीं है। किसी Activity की Classification के लिए Context, Behaviour और Supporting Evidence की आवश्यकता होती है।

NCII और Sextortion

रिपोर्ट में Non-Consensual Intimate Imagery (NCII) और Sextortion को Sensitive Investigation Categories के रूप में शामिल किया गया है।

TraceX Labs के अनुसार ऐसे मामलों में Evidence Handling के दौरान विशेष सावधानी आवश्यक है। Researchers को Sensitive Material को अनावश्यक रूप से Download, Reproduce या Redistribute नहीं करना चाहिए।

Public Security Reports में जरूरत पड़ने पर Redacted Evidence का इस्तेमाल किया जा सकता है।

संदिग्ध CSAM/CSE-related Infrastructure

रिपोर्ट का सबसे Sensitive हिस्सा Suspected CSAM/CSE-related Infrastructure से संबंधित है।

TraceX Labs ने इस Finding को “Suspected / Corroboration Required” के रूप में वर्गीकृत किया है। इसका अर्थ है कि उपलब्ध Indicators को अतिरिक्त Evidence और Corroboration के जरिए Verify करने की आवश्यकता है।

रिपोर्ट ऐसे मामलों में Evidence Handling को लेकर भी विशेष सावधानी की सलाह देती है। Suspected Illegal Material को अनावश्यक रूप से Download, Reproduce या Redistribute नहीं किया जाना चाहिए।

Deepfake और Synthetic Media

TraceX Labs की Research में Deepfake और Synthetic Media-related Spam को भी शामिल किया गया है।

रिपोर्ट के अनुसार केवल Synthetic या Manipulated Media की मौजूदगी से किसी Campaign का उद्देश्य निर्धारित नहीं किया जा सकता। Analysts को Content के साथ Distribution Channels, URLs, Redirects और संबंधित Infrastructure को भी Correlate करना चाहिए।

Malicious Redirection की जांच

रिपोर्ट में Redirect Behaviour को भी महत्वपूर्ण Investigation Area बताया गया है।

किसी Apps Script Web App का इस्तेमाल Intermediate Point के रूप में किया जा सकता है, जहां से User को किसी External Website या Resource पर भेजा जाता है।

इसलिए Security Teams को केवल Apps Script URL की जांच तक सीमित नहीं रहना चाहिए। पूरी Redirect Chain और Final Destination की जांच करना जरूरी हो सकता है।

Final Destination से Phishing Page, Malware Download, Scam Infrastructure या Campaign के अन्य Components के बारे में अतिरिक्त जानकारी मिल सकती है।

Google URL होने का मतलब Safe होना नहीं

TraceX Labs की रिपोर्ट का एक महत्वपूर्ण बिंदु यह है कि किसी URL का Google से जुड़ा होना अपने आप उसकी Safety या Legitimacy साबित नहीं करता।

Google-owned URL होने से यह साबित नहीं होता कि Google ने उस Content को बनाया या Endorse किया है अथवा Final Destination को Operate करता है। इसी तरह HTTPS का इस्तेमाल भी किसी Content के Legitimate होने का प्रमाण नहीं है।

इसलिए Security Teams को केवल Hosting Provider के नाम के बजाय वास्तविक Behaviour और Infrastructure को देखना चाहिए।

Security Teams कैसे पहचानें ऐसी गतिविधियां?

TraceX Labs ने Investigation के लिए कई स्तरों पर Data को Correlate करने की सलाह दी है।

URL Level पर Suspicious Apps Script URLs, Unusual Parameters, Repeated Deployment Identifiers और Known Malicious Destinations की जांच की जा सकती है।

Web Proxy Data से Redirect Chains, Final Destinations, Downloaded Files और MIME Types की जानकारी मिल सकती है।

Endpoint Telemetry से Unexpected APK Downloads, Suspicious File Execution, Browser-originated Downloads और Credential Submission जैसी गतिविधियों का पता लगाया जा सकता है।

रिपोर्ट में Apps Script URLs को इन Indicators के साथ Correlate करने की सलाह दी गई है:

Destination Domains

  • IP Addresses और ASNs
  • Certificates
  • URL Parameters
  • File Hashes
  • Redirect Chains
  • Related Campaign Infrastructure
  • Evidence-based Classification

TraceX Labs ने अपनी Research में Observed, Correlated, Suspected, Potential, Benign और Unknown जैसी Evidence Categories का इस्तेमाल किया है।

रिपोर्ट के अनुसार केवल किसी URL, Screenshot या Infrastructure Indicator के आधार पर Attribution, Criminal Intent, Ownership या Google से Affiliation स्थापित नहीं की जा सकती।

यह सावधानी विशेष रूप से CSAM/CSE, NCII और Sextortion जैसे Sensitive मामलों में महत्वपूर्ण है।

MITRE ATT&CK से Mapping

रिपोर्ट में संभावित गतिविधियों को कई MITRE ATT&CK Techniques से Map किया गया है। इनमें T1583.006 Web Services, T1583.007 Serverless, T1608.006 SEO Poisoning, T1608.001 Upload Malware और T1566.002 Phishing Link शामिल हैं।

रिपोर्ट में यह भी कहा गया है कि T1102 Web Service और T1567 Exfiltration Over Web Service जैसी Techniques का इस्तेमाल तभी किया जाना चाहिए जब संबंधित Behaviour वास्तव में देखा गया हो।

TraceX Labs का पांच चरणों वाला Investigation Model

रिपोर्ट में Security Teams के लिए एक Structured Investigation Model दिया गया है:

Discover → Validate → Correlate → Classify → Report

इस Framework का उद्देश्य किसी Suspicious Infrastructure को केवल एक Indicator के आधार पर वर्गीकृत करने के बजाय अलग-अलग Sources से प्राप्त Evidence को जोड़कर Analysis करना है।

TraceX Labs के Assessment के अनुसार Google Apps Script Infrastructure संभावित रूप से SEO Poisoning, Spam और Doorway Pages, Phishing और Fraud, Malware Distribution, Malicious Redirection, Adult और NSFW Spam, NCII और Sextortion, Suspected CSAM/CSE-related Infrastructure, Gambling और Betting, Drug-related Spam, Deepfake और Synthetic Media तथा Google Search और Video Spam जैसी गतिविधियों में दिखाई दे सकता है।

रिपोर्ट का मुख्य निष्कर्ष यह है कि Security Teams को केवल इस आधार पर किसी Infrastructure को संदिग्ध नहीं मानना चाहिए कि वह Google Apps Script पर Hosted है। Investigation में Behaviour, Content, Destination और अलग-अलग Infrastructure के बीच संबंध को Evidence के आधार पर एक साथ देखना अधिक महत्वपूर्ण है।

Research Source: TraceX Labs की Threat Intelligence Report

Next Story