Cyber Attacks

Google Docs commenting feature exploited for spear-phishing

0

A new trend in phishing attacks involves threat actors abusing the commenting feature of Google Docs to send out emails that appear trustworthy.

As Google itself is being “tricked” into sending out these emails, the chances of email security tools tagging them as potentially risky are very less.

The trick which emerged in December was actually under limited exploitation since October last year. Google tried to mitigate the issue, but they haven’t fully closed the vulnerability yet.

Google Docs is used by many employees, so most recipients of these emails are familiar with these notifications.

This recent campaign is monitored actively by threat analysts at Avanan.

Hackers use their Google account to create a Google Document and then comment it to mention the target with an @.

Google then sends a notification email to the target’s inbox, informing them that another user has commented on a document and mentioned them.

The comment on the email might include malicious links that lead to malware dropping web pages or phishing sites, so there are clearly no checking/filtering mechanisms in place.

Also, the threat actor’s email is not shown in the notification, and the recipient sees just a name. This makes impersonation very easy, and simultaneously raises the chances of success for the actors.

The same technique works on Google Slide comments as well, and Avanan reports having seen actors leveraging it on various elements of the Google Workspace service.

The attackers do not even have to share the document with their targets as mentioning them alone is enough to send malicious notifications.

According to Avanan, the threat actors behind these attacks appear to favor Outlook users, but the target demographic is not limited to them.

This ongoing spear-phishing campaign uses over 100 Google accounts and has already hit 500 inboxes across 30 organizations.

In order to mitigate the risk of these types of campaigns is to:

  • Confirm that the sender email matches your colleague’s (or claimed person)
  • Avoid clicking on links that arrive via email and are embedded on comments
  • Deploy additional security measures that apply stricter file-sharing rules on Google Workspace
  • Use an internet security solution from a trustworthy vendor that features phishing URL protection

Image Credits : Guiding Tech

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

New iOS malware fakes iPhone shutdown to spy on users

Previous article

1.1 million customer accounts compromised from 17 companies

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *