Google Docs Comment Feature is the Key to a New Wave of Phishing Campaigns

Stu Sjouwerman | Jan 20, 2022

Google Docs Comment Feature New Wave to PhishingHackers take advantage of legitimate comment functionality as a way to look legitimate, reach the Inbox, and avoid detection, despite using malicious links for phishing attacks.

Last month, security vendor Avanan observed a new wave of hackers using Google Docs’ comment feature as a means to target victims. In this attack, threat actors are sending malicious content via Google Docs using embedded links.

It’s quite brilliant, really. The attack is hosted on a Google domain (instant credibility), the victim is tagged using the @ and the user’s email address, the email is sent from Google (again, credibility), it looks like a business-related email (given the email is basically about the victim being tagged in a comment on a Google doc), the attacker’s email is not provided (only a “name”, which can be used to impersonate someone the victim knows) and it appears security solutions aren’t finding this malicious in nature.

Below is an example from Avanan:

Rw-kYSzG3su-O4vr38xVIh-fgvRRTAJgp5FIUuA_DU0wkEziq6iLMZs9pyFy6YqF0n3VOZxKCmIzi5x4M4N9F3GKkUUYVvkYKn1WCFnxdLohCothjyCMKPWeZWr-tXc3_FV_-gbk

Source: Avanan

The bottom line for any of these new kinds of phishing attacks is to educate users that if an email is unexpected at all, it should be assumed to be malicious until proven otherwise. A good continual Security Awareness Training program will not only teach users this level of vigilance, but continually reinforce the need to have a constant state of scrutiny whenever an unsolicited email is received.

Topics: Phishing

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.