Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - Geek before it was Chic.

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews




spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Macrium Reflect FREE Edition
3. Smart Defrag
4. Visual C++ Redistributable Runtimes AIO Repack
5. Visual C++ Runtime Installer (All-In-One)
6. McAfee Removal Tool (MCPR)
7. MusicBee
8. Rufus
9. K-Lite Mega Codec Pack
10. Sergei Strelec's WinPE
More >>

top reads

Star How to Disable 1-Click Ordering on Amazon (and Avoid Surprise Charges)

Star How to Fix Shallow Paint Layer Depth in Bambu Studio

Star Aviator Betting Game Secrets: Unlock 97% RTP & Triple Your Wins

Star Windows Recall: What It Is, Why Hackers Will Love It, and How to Stay Safe

Star Star Trek Fleet Command Promo Codes: Redeem Codes for Free Shards, Blueprints And Resources

Star How To Use VLC Media Player to Trim Video Clips

Star What Is the $WinREAgent Folder and Can I Delete It?

Star Swear Your Way to Better Search Results

Star How to Get a Dark Start Menu and Taskbar in Windows 10 & 11

Star Enable, Disable, Manage, Delete or Create a System Restore Point


MajorGeeks.Com » News » October 2012 » Requesting Sensitive Data Via Google Docs: Phishing Really is That Easy

Requesting Sensitive Data Via Google Docs: Phishing Really is That Easy


Contributed by: Email on 10/18/2012 03:21 PM [ comments Comments ]


Please leave your credit card number, its expiration date and security code, along with your full name and billing address in the comments section of this blog post. You’re obviously not going to do this. You know better, I know better, but there are those who don’t. So many, in fact, that scammers are not only comfortable with and willing to invest in scams no more or less complicated, but they are also confident that the scams will succeed.

Such is the case for a familiar social engineering campaign with a new twist. Securelist’s Vicente Diaz details an email-based scam in which attackers are attempting to pilfer various sensitive data simply by asking for it in a Google Doc attached to a phishing email. As has been a hallmark of traditional email-based phishing campaigns, the malicious link, which in this case leads to a Google Doc, is delivered via an email whose text is written in poorly constructed language. Diaz used an example written in Spanish.

Diaz initially thought the method was a novel one, but he quickly realized the Google Doc technique has already caught-on, in part because of the ease with which Google Docs bypass security products. Diaz notes that the method is also potent due to the seemingly legitimate appearance of Google Docs among victims.

Historically, the malicious links embedded in emails would lead to compromised websites serving malware or to domains masquerading as social media, banking, or other online login pages in order to steal credentials. However, in this case, the questionable link leads to a Google Doc, malicious only in its requests: asking for the usernames, email addresses, passwords, and dates of last access from its victims.

Diaz’s isn’t completely certain what the attackers are after, but he believes they are attempting to steal email authentication credentials.

For those of you unacquainted with how Google Docs work, recipients of a Doc input information, save it, and the updated document is automatically sent back to the Doc’s creator.

Diaz warns this is only the beginning. While Google Docs are a convenient medium for duping the unsuspecting into disclosing information they shouldn’t disclose, they are also convenient for hosting more malicious content like malware and executables.






« Ubuntu 12.10 (Final) released · Requesting Sensitive Data Via Google Docs: Phishing Really is That Easy · Survey: SMBs Remain Blissfully Unfazed by Cyberthreats »




Comments
comments powered by Disqus

MajorGeeks.Com » News » October 2012 » Requesting Sensitive Data Via Google Docs: Phishing Really is That Easy

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition