Researchers have discovered that threat actors are targeting users by leveraging Google’s cloud infrastructure to infect them with malware, according to Cyware. In these campaigns, threat actors utilize the Google Cloud infrastructure service to conduct phishing by attaching Google firebase storage URLs in phishing emails. Most of the themes for the lures include payment invoices, account verifications, upgrading email accounts, change-password emails, and much more. Once the targets click on the Firebase link, they land on a supposed login page and are required to enter their credentials, which are shared with the cybercriminals.

Subscribe
Notify of
guest
1 Expert Comment
Newest
Oldest Most Voted
Inline Feedbacks
View all comments
Jake Moore
Jake Moore , Cybersecurity Specialist
InfoSec Expert
June 2, 2020 10:19 am

Phishing scams are still very common, but particularly clever attempts are increasing and can deceive even those who are aware of them. In the moment, reading something which mounts pressure on you to verify or give up information can easily make you trip up and overlook a scam.

You simply cannot trust all emails, no matter what the body of the message says. Verifying authentic emails has never been more important, and remains your best bet in beating the fraudsters.

Companies that don\’t have the proper security procedures in place can often leave themselves and their customers vulnerable to a social engineering attack, but constant delivery of training is vital to make people aware of the problem and raise a zero-trust policy.

If you have fallen for a scam like this, it’s a race against the clock to reverse the damage caused, by calling the bank or changing all those passwords recently divulged.

Last edited 2 years ago by Jake Moore
1
0
Would love your thoughts, please comment.x
()
x