Google Docs commenting feature abused in phishing operations
Full article219 words · extracted from therecord.media · click to collapse
Threat actors are using the commenting feature of Google Docs files to lure users on phishing sites or to download malware-infected files. In a report today, email security firm Avanan said it has seen the technique being abused in malware distribution campaigns last month, in December 2021. The technique, first documented in the fall of 2020, is extremely simple to carry out and can be easily automated for mass attacks. Avanan says the technique is ideal for phishing and malware distribution because the threat actor's email address isn't shown, but just their self-configured name, which could be very easily be set to the name of another person from the same organization. In addition, all emails come from Google's systems, meaning they can't be stopped without blacklisting Google's email infrastructure. Avanan said it notified Google of the resurgence of this old technique in new campaigns, for which Google initially rolled out some detections back in 2020.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/google-docs-commenting-feature-abused-in-phishing-operations