Google Docs Phishing Campaign
ID: 3f9839d8-2467-5487-bc5f-aac76718c122
STIX ID: report--3f9839d8-2467-5487-bc5f-aac76718c122
Feed Name: Zscaler Security Research Blog
An aggressive phishing campaign leveraged squatted domains and a malicious web app that used Google OAuth to request permissions to read, send, delete, and manage victims' Gmail and contacts; once users granted access, the attackers used compromised accounts to send the phishing link to the victims' contacts, rapidly propagating the campaign. The report details campaign flow, screenshots of the phishing messages and OAuth prompts, ~10 newly registered domains used as IOCs, and observed traffic (over 10,000 hits in two hours), and notes Google and Zscaler mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
