symantec logo

A new sophisticated phishing that uses Google Docs and Google Drive

We watch phishing μηνύματα κάθε μέρα, αλλά πρόσφατα ένα ξεχώρισε: μια εξελιγμένη απάτη με στόχο τα διαπιστευτήρια σύνδεσης των χρηστών του Google Docs και του Google Drive. Την απάτη την ανακάλυψε πρόσφατα η

Symantec logo

Fraud comes by e-mail, it has a simple "Documents" theme and invites the recipient to see an important document in Google Docs by clicking on the link included.
Of course, o it doesn't go to Google Docs, but it supposedly takes you to Google, presenting a very convincing fake Google Docs login page:

phish_site_image
The fake page is hosted on Google servers and is served through SSL, making the page even more convincing. Fraudsters have just created a public folder within a Google Drive account, uploaded a file, used the Google Drive Preview feature, and got a publicly accessible URL that they include in their messages.

This login page will look familiar to many Google users as it is now used across all of them of Google. It mentions which service it gives access to, but that's a subtlety that many won't notice.

Αν κάποιος πατήσει το "Σύνδεση ", τα διαπιστευτήρια του χρήστη αποστέλλονται σε ένα PHP script που βρίσκεται σε έναν hacked .

This page then redirects to a real Google Docs document, making the whole attack very convincing. Google accounts are a valuable goal for phishers, since they can use them to access many services.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).