Google Docs used for Office 365 credential phishing
#1
Exclamation 
Quote:
[Image: office-365-phishing-via-gdocs-featured.jpg]

Phishers are using Google online services to take over Microsoft online service accounts.

Since the onset of the COVID-19 pandemic, many companies have moved much of their workflows online and learned to use new collaboration tools. In particular, Microsoft’s Office 365 suite has seen a lot more use — and, to no one’s surprise, phishing now increasingly targets those user accounts.

Scammers have been resorting to all sorts of tricks to get business users to enter their passwords on a website made to look like Microsoft’s sign-in page.

Here is another phishing scheme that makes use of Google services.

Phishing letter

As most phishing schemes, this one begins with a letter (and link) similar to this one.

The unclear message from an unknown sender concerns some kind of deposit and includes a link having to do with “Deposit Advice.” The letter asks the recipient to check on the deposit type or confirm the sum. Now, although security systems alert recipients about the letter coming from outside the company, the link “to the file” passes muster because it connects to a legitimate Google online service, not a phishing site.

Phishing site

The link leads to a location that appears to be the OneDrive corporate service page. Users can even see that the document is available to any company user (made so likely in hopes someone will forward the link to a corporate accountant).

But the screen users see is not truly a Web page; it’s a slide from a Google Docs presentation that automatically opens in View mode. The Open button on it can conceal any link at all. In this case, the link connects to a phishing page disguised as an Office 365 sign-in page.

Red flags

To begin with, the letter looks weird. You should not trust — let alone forward — a letter whose source and purpose isn’t clear. In this case, for example, if you weren’t involved in a deposit, then perhaps you shouldn’t be taking any action regarding that deposit.

More evidence:
  • Letters from external sources don’t tend to link to a company’s internal documents;
  • Real financial documents are set to open for specific people, not every single person in an organization;
  • The filename in the letter does not match the one allegedly stored on OneDrive;
  • Google Docs does not host Microsoft OneDrive pages (see the browser address bar);
  • OneDrive is not Outlook, and an Open button in OneDrive should not lead to an Outlook sign-in page;
  • Outlook sign-in pages do not reside on Amazon websites (another browser address bar clue).
Each inconsistency should raise a flag, and together, they can leave no doubt: This is not a safe place for your Office 365 credentials.
...
Continue Reading
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Sandboxie Plus (open source fork of San...
Release v1.15.11 /...Kool — 10:16
NVIDIA announces GeForce RTX 5060 Ti at ...
NVIDIA intros RTX ...harlan4096 — 09:38
Java Runtime Environment 8.0 Update 451
Java Runtime Envir...harlan4096 — 08:29
Google Chrome 135.0.7049.95/.96
Stable Channel Upd...harlan4096 — 08:26
Adobe Acrobat Reader DC 25.001.20458
Adobe Acrobat Read...harlan4096 — 08:20

[-]
Birthdays
Today's Birthdays
avatar (49)fuspeukChark
avatar (43)werriewWaiNg
avatar (37)Freemanleo
Upcoming Birthdays
avatar (44)wapedDow
avatar (48)oapedDow
avatar (41)Sanchowogy
avatar (43)techlignub
avatar (42)Stevenmam
avatar (49)onlinbah
avatar (50)steakelask
avatar (44)Termoplenka
avatar (42)bycoPaist
avatar (48)pieloKat
avatar (42)ilyagNeexy
avatar (50)donitascene
avatar (50)Toligo
avatar (37)RobertUtelt

[-]
Online Staff
There are no staff members currently online.

>