Cybercriminals Host Malicious Payloads on Google Cloud Storage
#1
Quote:A malicious email campaign targeting employees of banks and financial services companies in the United States and the United Kingdom has been abusing Google Cloud Storage for payload delivery, Menlo Labs security researchers say.

As part of the attacks, the malicious actor attempts to trick users into clicking on malicious links to archive files such as .zip or .gz. The malicious payloads, which the researchers identified as being part of the Houdini and QRat malware families, were hosted on storage.googleapis.com, the domain of the Google Cloud Storage service.

With the service used by countless companies, malicious actors can bypass security controls in place within organizations or built into commercial security products by simply hosting their payloads on the domain — the practice isn’t new.

“These attackers may have chosen to use malicious links rather than malicious attachments because of the combined use of email and the web to infect victims with this threat. Many email security products can detect malicious attachments, but identify malicious URLs only if they are already in their threat repositories,” Menlo’s security researchers explain.

Source: https://www.securityweek.com/cybercrimin...ud-storage
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Messages In This Thread
Cybercriminals Host Malicious Payloads on Google Cloud Storage - by silversurfer - 20 December 18, 14:55

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Microsoft Edge 149.0.4022.80
Release Summary ...harlan4096 — 15:38
AdGuard VPN for Windows 2.9.4
AdGuard VPN for Wi...harlan4096 — 08:24
Mozilla Firefox Browser 152.0.1
Mozilla Firefox Br...harlan4096 — 06:28
K-Lite Codec Pack 19.8.2 / 19.8.2 Update
Changes in 19.8.2:...harlan4096 — 06:26
HandBrake finally scales better on AMD T...
AMD fixes HandBrak...harlan4096 — 06:24

[-]
Birthdays
Today's Birthdays
avatar (48)kinotHeemn
avatar (39)Ceballos1976
Upcoming Birthdays
avatar (39)Tedscolo
avatar (46)brakasig
avatar (40)efynu

[-]
Online Staff
There are no staff members currently online.

>