← ~/fraud-of-shame

obsidianly GCS Phish Stager Pwned

October 2026 · Alardiians / Razorhack · Cloud misconfig

TL;DR: A spam campaign hid behind storage.googleapis.com/obsidianly/obsidianly.html. That is real Google hosting, attacker-owned bucket. The stager was a static HTML/JS redirect, not a vulnerable app. The bucket allowed anonymous create/update/delete, so the landing page got replaced with a warning (and a little culture).

// what the link was

Emails pushed fake “cloud storage full / payment failed” urgency and linked to URLs like:

https://storage.googleapis.com/obsidianly/obsidianly.html?act=cl&pid=…&vid=…

Mail filters like the hostname because storage.googleapis.com is Google. Everything after the first path segment is just a bucket name the scammer registered. Query params (act, pid, vid, etc.) were affiliate tracking for the scam funnel.

With act=cl, the stager sent the browser to a second hop on DigitalOcean Spaces. Same campaign family as older GCS buckets like flores/flores.html; only the bucket names rotate.

// where it sends you

The payload is a static fake “Cloud” billing page: subscription renewal failed, storage 100% full, renew now or your files get deleted. Generic branding, countdown pressure, and a card form. It is not Google, Apple, or your real cloud provider.

Example destination (tracking params trimmed): https://secure-mmm3.nyc3.digitaloceanspaces.com/cloud_billing_v6zNEW2-sec2pay.html?cep=…&lptoken=…&clickid=…

Other spins use the same HTML name on different Spaces hosts (*.sfo3.digitaloceanspaces.com, *.nyc3.digitaloceanspaces.com, etc.). Long cep / lptoken query strings carry affiliate and click tracking. Do not enter payment details.

// recon

  1. Fetch the object (static HTML, no app server).
  2. List the bucket anonymously: GET https://storage.googleapis.com/storage/v1/b/obsidianly/o
  3. Probe write with a throwaway filename before touching the live phish file.
curl.exe -s "https://storage.googleapis.com/storage/v1/b/obsidianly/o"
curl.exe -s -w "\nHTTP:%{http_code}\n" -X PUT ^
  "https://storage.googleapis.com/obsidianly/_probe.txt" ^
  -H "Content-Type: text/plain" -d "probe"

HTTP 200 on PUT plus a readable object means world-writable IAM (usually allUsers with object create/update/delete). Resumable upload init returned 200 as well. Anonymous DELETE worked on probe files.

// what we did

Google Cloud Storage just serves static objects. Owning the redirect page means uploading a new obsidianly.html over the old one, same as the phishers did when they first stood it up.

After confirming write access, we overwrote obsidianly.html with a warning page for anyone who clicked the spam link: storage is fine, it was phishing, signed by Alardiians / Razorhack, plus remediation notes for the bucket admin and a mandatory awareness stream.

Live stager (may change if someone else writes the bucket again): storage.googleapis.com/obsidianly/obsidianly.html

// CDN cache annoyance

GCS edge caching can serve an old copy for up to an hour after you upload. Use a cache buster query string, hard refresh, or check object metadata via the JSON API (generation, updated). Setting Cache-Control: no-cache, no-store, max-age=0 on upload helps after the stale entry ages out.

// if you admin this bucket

Own this bucket? Strangers can still create, overwrite, and delete objects. Uniform bucket-level access is on, so check IAM on the bucket and on the project it lives in.

  1. Cut public write: Remove allUsers and allAuthenticatedUsers from any role that can create, update, or delete objects.
  2. Clean house: List objects, remove junk, restore a known-good copy if you have one.
  3. Pick your public read story: Need direct storage.googleapis.com links? allUsers gets Storage Object Viewer only. Otherwise enforce public access prevention and keep the bucket private.
  4. Check the logs: Admin Activity for IAM edits; Data Access for object writes if logging was enabled (off by default).
  5. Keys and accounts: Public write is usually misconfiguration. Revoke leaked keys if you find them.
  6. Prove it is fixed: Logged-out probe upload should fail. Consider soft delete and versioning.

// report it properly

Defacing one GCS file does not kill the campaign. They rotate bucket names on both Google and DigitalOcean. Report the Google stager: Google Cloud abuse and Safe Browsing. Report the billing page URL to DigitalOcean abuse with the full Spaces link you received.

// proof

Scammers: get rekt. Everyone else: stay suspicious of Google-shaped links.