{"id":7521,"date":"2017-05-03T13:11:15","date_gmt":"2017-05-03T21:11:15","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/05\/03\/news-1306\/"},"modified":"2017-05-03T13:11:15","modified_gmt":"2017-05-03T21:11:15","slug":"news-1306","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2017\/05\/03\/news-1306\/","title":{"rendered":"Google Docs App spam goes phishing"},"content":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Wed, 03 May 2017 19:51:53 +0000<\/strong><\/p>\n<p>There&#8217;s a very clever phishing scam going around at the moment &#8211; originally thought to be <a href=\"https:\/\/twitter.com\/sarahjeong\/status\/859840520767422464\" target=\"_blank\">targeting journalists<\/a> given the sheer number of them mentioning it on their Twitter feeds, it&#8217;s also been slinging its way across <a href=\"https:\/\/twitter.com\/ThatWeissGuy\/status\/859846505150205953\" target=\"_blank\">unrelated mailboxes<\/a> &#8211; from <a href=\"https:\/\/twitter.com\/GossiTheDog\/status\/859870758637621249\" target=\"_blank\">orgs<\/a> to schools\/campuses. This doesn&#8217;t mean it didn&#8217;t begin with a popped journo mailbox and spread its way out from there or that someone didn&#8217;t intentionally send it to a number of journalists of course &#8211; but either way, this one has gone viral and not in a &#8220;look at the cute cat pic&#8221; fashion.<\/p>\n<h3>Here&#8217;s how it happens<\/h3>\n<p>The potential victim receives an email claiming to be from a Mailnator account, which <a href=\"https:\/\/twitter.com\/mailinator\/status\/859851197091655680\" target=\"_blank\">they dispute<\/a>\u00a0is related to their service.<\/p>\n<p>The email reads as follows:<\/p>\n<blockquote>\n<p><strong>Title: [Contact] has shared a document on Google Docs with you<\/strong><\/p>\n<p><strong>Body: [Contact] has invited you to view the following document<\/strong><\/p>\n<\/blockquote>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/docs-spam.jpg\" data-rel=\"lightbox-0\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-17816\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/docs-spam-300x243.jpg\" alt=\"docs spam\" width=\"300\" height=\"243\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/docs-spam-300x243.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/docs-spam.jpg 511w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>Hitting the Google-styled &#8220;Open in Docs&#8221; button takes the clicker to a genuine Google sign-in page, which is sure to wrong-foot many people:<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/sign-in.jpg\" data-rel=\"lightbox-1\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-17817\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/sign-in-231x300.jpg\" alt=\"sign in\" width=\"231\" height=\"300\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/sign-in-231x300.jpg 231w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/sign-in-463x600.jpg 463w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/sign-in.jpg 515w\" sizes=\"auto, (max-width: 231px) 100vw, 231px\" \/><\/a><\/p>\n<p>Where this all goes wrong is on the next page, which is where the victim actually gives the app permission to access the account. Somehow, nobody at Google thought of preventing people from calling their apps &#8220;Google Docs&#8221;.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/app-permission.jpg\" data-rel=\"lightbox-2\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-17818\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/app-permission-258x300.jpg\" alt=\"app permission\" width=\"258\" height=\"300\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/app-permission-258x300.jpg 258w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/app-permission.jpg 509w\" sizes=\"auto, (max-width: 258px) 100vw, 258px\" \/><\/a><\/p>\n<blockquote>\n<p><strong>Google Docs would like to<\/strong><\/p>\n<p><strong>Read, send, delete and manage your email<\/strong><\/p>\n<p><strong>Manage your contacts<\/strong><\/p>\n<\/blockquote>\n<p>After &#8220;Allow&#8221; is hit, the spam is then sent on to contacts. While 2FA would normally save you from a phishing attempt, in this case, the victim is <a href=\"https:\/\/twitter.com\/pwnallthethings\/status\/859856461329035265\" target=\"_blank\">willingly giving permission to the app<\/a> so 2FA won&#8217;t help &#8211; the only solution is to see which <a href=\"https:\/\/myaccount.google.com\/intro\/security?target=permissions#connectedapps\" target=\"_blank\">apps have been granted permission<\/a> and revoke.<\/p>\n<p>Here are some of the domains being used for this (all offline at the time of writing, but there may be others):<\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"en\">Phish domains:<br \/> g-cloud[.]pro<br \/> docscloud[].win<br \/> docscloud[.]download<br \/> docscloud[.]info<br \/> g-cloud[.]win<br \/> g-docs[.]pro<br \/> gdocs[.]download<br \/> gdocs[.]pro<\/p>\n<p>\u2014 Andre M. DiMino (@sempersecurus) <a href=\"https:\/\/twitter.com\/sempersecurus\/status\/859849323462393857\">May 3, 2017<\/a><\/p>\n<\/blockquote>\n<p>Google is <a href=\"https:\/\/twitter.com\/gmail\/status\/859851013448224774\" target=\"_blank\">aware<\/a> of the situation and is currently working on it. Meanwhile, Cloudflare <a href=\"https:\/\/twitter.com\/xxdesmus\/status\/859865550033272833\" target=\"_blank\">leapt into action<\/a> very quickly. We&#8217;ll update the post with more information as\u00a0it comes in.<\/p>\n<p><em>Christopher Boyd (Thanks to <a href=\"https:\/\/twitter.com\/diodesign\" target=\"_blank\">DioDesign<\/a> and\u00a0<a href=\"https:\/\/twitter.com\/hrbrmstr\" target=\"_blank\">hrbrmstr<\/a> for <\/em>screens\/data<em>)<\/em><\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/05\/google-docs-app-spam-goes-phishing\/\">Google Docs App spam goes phishing<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/05\/google-docs-app-spam-goes-phishing\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Wed, 03 May 2017 19:51:53 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/05\/google-docs-app-spam-goes-phishing\/' title='Google Docs App spam goes phishing'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2014\/02\/google.gif' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>There&#8217;s a very clever phishing scam going around at the moment involving Google Docs App. Originally thought to be targeting journalists given the sheer number of them mentioning it on their Twitter feeds, it&#8217;s also been slinging its way across unrelated mailboxes &#8211; from orgs to schools\/campuses.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/\" rel=\"category tag\">Cybercrime<\/a><\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/social-engineering-cybercrime\/\" rel=\"category tag\">Social engineering<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/google\/\" rel=\"tag\">Google<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/google-docs\/\" rel=\"tag\">google docs<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/mailnator\/\" rel=\"tag\">Mailnator<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/phish\/\" rel=\"tag\">phish<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/phishing\/\" rel=\"tag\">phishing<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/spam\/\" rel=\"tag\">spam<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/05\/google-docs-app-spam-goes-phishing\/' title='Google Docs App spam goes phishing'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/05\/google-docs-app-spam-goes-phishing\/\">Google Docs App spam goes phishing<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[4503,1670,12143,12144,10511,3924,10510,10518],"class_list":["post-7521","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-cybercrime","tag-google","tag-google-docs","tag-mailnator","tag-phish","tag-phishing","tag-social-engineering","tag-spam"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/7521","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=7521"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/7521\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=7521"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=7521"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=7521"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}