Attackers Abuse Google Drawings to Host Phishing Pages
Researchers at Menlo Security warn that a phishing campaign is exploiting Google Drawings to evade security filters.
The phishing emails inform the user that their Amazon account has been suspended, instructing them to click on a link in order to update their information and reactivate their account.
The phishing page is crafted with Google Drawings, which makes it more likely to fool humans while evading detection by security technologies.
“This graphic is actually hosted in Google Drawings, part of the Google Workspace suite, that allows users to collaborate on graphics,” the researchers write.
“Such a site is not typically blocked by traditional security tools. Another thing that makes Google Drawings appealing in the beginning of the attack is that it allows users (in this case, the attacker) to include links in their graphics. Such links may easily go unnoticed by users, particularly if they feel a sense of urgency around a potential threat to their Amazon account.”
The attackers are also abusing link shorteners to further increase the chances that the phishing link will bypass security filters.
“We believe that ‘l.wl.co’ was chosen because shortened WhatsApp links created with this service do not present any type of warning to the user that they are being redirected to a different site altogether,” the researchers note. “As an extra precautionary measure, the link created with the WhatsApp URL shortener is then appended with another URL shortener, “qrco[.]de,” which is a URL shortener service for dynamic QR codes. We believe that this second step is designed to obfuscate the original link still further, in an effort to evade security URL scanners.”
KnowBe4 empowers your workforce to make smarter security decisions every day. Over 65,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.
Menlo Security has the story.
Free Phishing Security Test
Would your users fall for convincing phishing attacks? Take the first step now and find out before bad actors do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.
Here’s how it works:
- Immediately start your test for up to 100 users (no need to talk to anyone)
- Select from 20+ languages and customize the phishing test template based on your environment
- Choose the landing page your users see after they click
- Show users which red flags they missed, or a 404 page
- Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
- See how your organization compares to others in your industry
PS: Don’t like to click on redirected buttons? Cut & Paste this link in your browser: https://info.knowbe4.com/phishing-security-test-partner?partnerid=001a000001lWEoJAAW