storage.googleapis.com/obsidianly/obsidianly.html.
That is real Google hosting, attacker-owned bucket. The stager was a static HTML/JS redirect, not a vulnerable app.
The bucket allowed anonymous create/update/delete, so the landing page got replaced with a warning (and a little culture).
Emails pushed fake “cloud storage full / payment failed” urgency and linked to URLs like:
https://storage.googleapis.com/obsidianly/obsidianly.html?act=cl&pid=…&vid=…
Mail filters like the hostname because storage.googleapis.com is Google.
Everything after the first path segment is just a bucket name the scammer registered.
Query params (act, pid, vid, etc.) were affiliate tracking for the scam funnel.
With act=cl, the stager sent the browser to a second hop on DigitalOcean Spaces.
Same campaign family as older GCS buckets like flores/flores.html; only the bucket names rotate.
The payload is a static fake “Cloud” billing page: subscription renewal failed, storage 100% full, renew now or your files get deleted. Generic branding, countdown pressure, and a card form. It is not Google, Apple, or your real cloud provider.
Example destination (tracking params trimmed):
https://secure-mmm3.nyc3.digitaloceanspaces.com/cloud_billing_v6zNEW2-sec2pay.html?cep=…&lptoken=…&clickid=…
Other spins use the same HTML name on different Spaces hosts (*.sfo3.digitaloceanspaces.com, *.nyc3.digitaloceanspaces.com, etc.).
Long cep / lptoken query strings carry affiliate and click tracking. Do not enter payment details.
GET https://storage.googleapis.com/storage/v1/b/obsidianly/ocurl.exe -s "https://storage.googleapis.com/storage/v1/b/obsidianly/o"
curl.exe -s -w "\nHTTP:%{http_code}\n" -X PUT ^
"https://storage.googleapis.com/obsidianly/_probe.txt" ^
-H "Content-Type: text/plain" -d "probe"
HTTP 200 on PUT plus a readable object means world-writable IAM (usually allUsers with object create/update/delete).
Resumable upload init returned 200 as well. Anonymous DELETE worked on probe files.
Google Cloud Storage just serves static objects. Owning the redirect page means uploading a new obsidianly.html over the old one, same as the phishers did when they first stood it up.
After confirming write access, we overwrote obsidianly.html with a warning page for anyone who clicked the spam link:
storage is fine, it was phishing, signed by Alardiians / Razorhack, plus remediation notes for the bucket admin and a mandatory awareness stream.
Live stager (may change if someone else writes the bucket again): storage.googleapis.com/obsidianly/obsidianly.html
GCS edge caching can serve an old copy for up to an hour after you upload.
Use a cache buster query string, hard refresh, or check object metadata via the JSON API (generation, updated).
Setting Cache-Control: no-cache, no-store, max-age=0 on upload helps after the stale entry ages out.
Own this bucket? Strangers can still create, overwrite, and delete objects. Uniform bucket-level access is on, so check IAM on the bucket and on the project it lives in.
allUsers and allAuthenticatedUsers from any role that can create, update, or delete objects.storage.googleapis.com links? allUsers gets Storage Object Viewer only. Otherwise enforce public access prevention and keep the bucket private.Defacing one GCS file does not kill the campaign. They rotate bucket names on both Google and DigitalOcean. Report the Google stager: Google Cloud abuse and Safe Browsing. Report the billing page URL to DigitalOcean abuse with the full Spaces link you received.
x-goog-generation on each overwrite.