Sunday, September 6, 2026

Cybercriminals Using Trusted Google Domains to Spread Malicious Code

A sophisticated new malvertising scheme has emerged, transforming trusted e-commerce websites into phishing traps without the knowledge of site owners or advertisers.

Cybercriminals are exploiting integrations with Google APIs, specifically through JSONP (JSON with Padding) calls, to inject malicious scripts into legitimate online stores.

These scripts operate covertly, redirecting unsuspecting shoppers to fraudulent payment pages where they are tricked into disclosing sensitive credit card information under the guise of paying trusted merchants.

Unlike traditional malvertising campaigns that rely on suspicious ads or overt redirects, this attack leverages the credibility of high-quality sites and clean ad placements, making it particularly insidious.

Shoppers clicking on legitimate advertisements are led to real storefronts, only to encounter invisible threats hidden beneath the surface.

A notable case involved Ray-Ban’s Indian store (india.ray-ban.com), where attackers compromised the site’s backend, turning a trusted brand into an unwitting phishing platform.

This double-edged strategy allows attackers to hijack brand credibility while exploiting the victimized companies’ marketing efforts to drive traffic to their scams all without investing in distribution.

Exploiting Legitimate E-Commerce Sites for Phishing

The core of this attack lies in the exploitation of JSONP, a now-outdated technique used to bypass the browser’s same-origin policy by loading data from external domains via script tags.

Google Domains
 Example of script execution

JSONP responses execute immediately upon loading, offering no control over the content and posing significant security risks, including susceptibility to cross-site scripting (XSS) attacks.

If an attacker compromises an API endpoint, they can inject malicious JavaScript that executes unchecked.

Complicating matters further, even robust Content Security Policy (CSP) configurations often fail to block these payloads because trusted domains like Google’s are explicitly allowed.

Vulnerable Google APIs, such as translate.googleapis.com, accounts.google.com, and www.youtube.com, have been identified as vectors for delivering these malicious scripts.

This vulnerability, initially uncovered by Source Defense’s research team and reported to Google on November 19, 2024 (Issue ID: 379818473), enables attackers to bypass conventional defenses and target users on legitimate platforms.

JSONP Vulnerabilities in Google APIs

The attack chain often culminates in redirects to fake payment pages hosted on malicious domains like montina[.]it or premium[.]vn, as evidenced by captured network traffic from compromised sites.

Google Domains
The Fake Payment Page

Many affected e-commerce platforms, including those running Adobe Commerce and Magento, have shown evidence of multiple injected scripts, amplifying the risk to users.

Despite the threat being disclosed to Google in November 2024, several compromised websites remain active, continuing to expose users to phishing risks.

The persistence of this attack, though currently small in scale, is alarming due to its sophistication and ability to weaponize trusted infrastructure.

Beyond phishing, attackers can exploit these vulnerabilities for auto-redirect attacks, silently funneling users to scam pages without any interaction, which severely erodes user trust and damages publisher reputation.

The case of india.ray-ban.com, previously compromised via the CosmicSting vulnerability, highlights the recurring nature of such threats, even though the site has since been remediated.

As cybercriminals continue to exploit trusted domains like Google’s to deliver malicious payloads, constant vigilance and proactive monitoring for suspicious script injections are critical.

This evolving threat underscores the need for enhanced security measures to protect users and preserve the integrity of legitimate online platforms in the face of increasingly covert attacks.

Find this News Interesting! Follow us on Google News, LinkedIn, & X to Get Instant Updates!

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Chainguard Hits 1 Billion Build Manifests With AI-Powered Software Supply Chain Security

Chainguard has surpassed 1 billion container build manifests, doubling...

Russian Hackers Deploy New HOOKEDGE Backdoor in Espionage Attacks Across Europe

Russian state-sponsored threat actor BlueDelta, also tracked as APT28,...

New Panzer Ransomware Hits 16 Victims Across 11 Countries With Data Theft and Encryption

Panzer ransomware has emerged as a new Ransomware-as-a-Service (RaaS)...

12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged...

Hackers Use Frontier AI Agents to Breach Enterprise Network in Under 10 Hours

A threat actor used frontier artificial-intelligence models and attack-specific...

CARS24 Data Breach Exposes 3,100 Customer Records, Leads Allegedly Sold for ₹1,000 Each

Used-car platform CARS24 has alleged that confidential information belonging...

Hackers Turn HiveMQ and Element Messenger Into Control Channels for Windows Backdoors

The financially motivated threat actor Toy Ghouls has expanded...

Related Articles

Recent News