Google Docs Comment Feature is the Key to a New Wave of Phishing Campaigns



Google Docs Comment Feature New Wave to PhishingHackers take advantage of legitimate comment functionality as a way to look legitimate, reach the Inbox, and avoid detection, despite using malicious links for phishing attacks.

Last month, security vendor Avanan observed a new wave of hackers using Google Docs’ comment feature as a means to target victims. In this attack, threat actors are sending malicious content via Google Docs using embedded links.

It’s quite brilliant, really. The attack is hosted on a Google domain (instant credibility), the victim is tagged using the @ and the user’s email address, the email is sent from Google (again, credibility), it looks like a business-related email (given the email is basically about the victim being tagged in a comment on a Google doc), the attacker’s email is not provided (only a “name”, which can be used to impersonate someone the victim knows) and it appears security solutions aren’t finding this malicious in nature.

Below is an example from Avanan:

Rw-kYSzG3su-O4vr38xVIh-fgvRRTAJgp5FIUuA_DU0wkEziq6iLMZs9pyFy6YqF0n3VOZxKCmIzi5x4M4N9F3GKkUUYVvkYKn1WCFnxdLohCothjyCMKPWeZWr-tXc3_FV_-gbk

Source: Avanan

The bottom line for any of these new kinds of phishing attacks is to educate users that if an email is unexpected at all, it should be assumed to be malicious until proven otherwise. A good continual Security Awareness Training program will not only teach users this level of vigilance, but continually reinforce the need to have a constant state of scrutiny whenever an unsolicited email is received.


Free Phishing Security Test

Would your users fall for convincing phishing attacks? Take the first step now and find out before bad actors do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.

PST ResultsHere's how it works:

  • Immediately start your test for up to 100 users (no need to talk to anyone)
  • Select from 20+ languages and customize the phishing test template based on your environment
  • Choose the landing page your users see after they click
  • Show users which red flags they missed, or a 404 page
  • Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
  • See how your organization compares to others in your industry

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/phishing-security-test-offer

Topics: Phishing



Subscribe to Our Blog


Comprehensive Anti-Phishing Guide




Get the latest about social engineering

Subscribe to CyberheistNews