Ghost in the Script: Impersonating Google App Script projects for stealthy persistence
Article originally co-authored with Jakub Pavlik on Exaforce's blog: https://www.exaforce.com/blogs/ghost-in-the-script
The ins and outs of Apps Script






Abusing Apps Script impersonation on a GCP Organization
Cryptomining Instance





Persist on the Organization using a Service Account inside a hidden project

Why even impersonate an Apps Script project?


Detecting the abuse of Apps Script projects
Finding project impersonation by looking at the billing information of the project

Blending the project in by modifying billing information


Finding occurrences of an App Script project impersonation through enabled API Services

Blending in by disabling API endpoints


Finding occurrences of an App Script project impersonation in the Logs

Limiting Project Impersonation using organization policies


Preventative controls
Stealthy persistence and defense
PreviousTo CNAME or not to CNAME: That is the (Enumeration) QuestionNextThe log rings don’t lie: historical enumeration in plain sight
Last updated