Phishing via Google Tasks
#1
Bug 
Quote:Attackers are delivering phishing links via Google Tasks notifications.
 
We’ve written time and again about phishing schemes where attackers exploit various legitimate servers to deliver emails. If they manage to hijack someone’s SharePoint server, they’ll use that; if not, they’ll settle for sending notifications through a free service like GetShared. However, Google’s vast ecosystem of services holds a special place in the hearts of scammers, and this time Google Tasks is the star of the show. As per usual, the main goal of this trick is to bypass email filters by piggybacking the rock-solid reputation of the middleman being exploited.

What phishing via Google Tasks looks likeThe recipient gets a legitimate notification from an @google.com address with the message: “You have a new task”. Essentially, the attackers are trying to give the victim the impression that the company has started using Google’s task tracker, and as a result they need to immediately follow a link to fill out an employee verification form.

[Image: google-tasks-phishing-notification.png]

To deprive the recipient of any time to actually think about whether this is necessary, the task usually includes a tight deadline and is marked with high priority. Upon clicking the link within the task, the victim is presented with an URL leading to a form where they must enter their corporate credentials to “confirm their employee status”. These credentials, of course, are the ultimate goal of the phishing attack.

Continue Reading...
Reply


Messages In This Thread
Phishing via Google Tasks - by harlan4096 - 3 hours ago

Forum Jump:


Users browsing this thread: 2 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Adobe Acrobat Reader DC 25.001.21223
Adobe Acrobat Reade...harlan4096 — 11:29
Vivaldi 7.8 Build 3925.70
Vivaldi 7.8 Build ...harlan4096 — 11:28
Free Download Manager 6.33.1.6644
Changes in 6.33.1....harlan4096 — 11:10
Phishing via Google Tasks
Attackers are deli...harlan4096 — 11:08
Kaspersky\VPN\KSOS 21.25 (MR25) & KES 1...
harlan4096 — 11:06

[-]
Birthdays
Today's Birthdays
avatar (38)showercurtains
avatar (49)PeterWhink
Upcoming Birthdays
avatar (46)dimaWeami
avatar (38)Michaelaburi
avatar (46)dpascoal
avatar (44)Baihu

[-]
Online Staff
There are no staff members currently online.

>