Medium Severity

Link: Google Cloud Storage /index and /unsub link pair

Description

This rule detects inbound messages that abuse Google Cloud Storage (storage.googleapis.com) hosting by embedding exactly two distinct links that share the same bucket directory, with paths following an /index and /unsub pattern. This structure is commonly seen in bulk spam campaigns promoting wellness products, supplement pitches, or reward/loyalty offers, where the hosted content serves as a landing page and the second link mimics an unsubscribe mechanism to lend legitimacy. The use of a trusted cloud storage domain helps the messages evade reputation-based filtering while funneling recipients to spam content.

References

No references.

Sublime Security
Created Oct 6th, 2026 • Last updated Oct 6th, 2026
Source
type.inbound
// two distinct paths
and length(distinct(map(filter(body.links,
                               .href_url.domain.domain == "storage.googleapis.com"
                        ),
                        .href_url.path
                    )
           )
) == 2
// they are exactly /<bucket>/index or /<bucket>/unsub
and all(distinct(map(filter(body.links,
                            .href_url.domain.domain == "storage.googleapis.com"
                     ),
                     .href_url.path
                 )
        ),
        regex.imatch(., '/[^/]+/(?:index|unsubv?)')
)
// all within the same bucket
and length(distinct(map(filter(body.links,
                               .href_url.domain.domain == "storage.googleapis.com"
                        ),
                        regex.extract(.href_url.path, '^/(?P<bucket>[^/]+)/')[0].named_groups["bucket"]
                    )
           )
) == 1
MQL Rule Console
•Docs•Learning Labs

Playground

Test against your own EMLs or sample data.

Share

Post about this on your socials.

Get Started. Today.

Managed or self-managed. No MX changes.

Deploy and integrate a free Sublime instance in minutes.
Get Started