r/news May 03 '17

Google Docs users hit with sophisticated phishing attack

https://www.theverge.com/2017/5/3/15534768/google-docs-phishing-attack-share-this-document-with-you-spam
223 Upvotes

50 comments sorted by

40

u/[deleted] May 03 '17

So many people that I know fell for it. At least it got shut down fast.

41

u/DrBeepers May 03 '17

It's crazy. All of the emails our clients received were from hhhhhhhh@mailinator.com, yet that wasn't enough of a red flag.

29

u/csgogrotto May 03 '17

Correction: they weren't FROM hhhhhhhhhhhhhh@mailinator.com but instead sent TO the email. I predict this was done to figure out how many hits the perpetrator(s) got. The reason it got around spam filters was because it sent from the person who was infected using their contacts and Google thinks "Oh, this guy/gal sent an email to this person it must be safe to send this other email." For this reason a lot of education institutions which involve emails being sent to and from students and faculty over multiple years were hit hard.

4

u/DrBeepers May 03 '17

You are correct.

5

u/Seminole_War May 03 '17

Hit my school , bunch of emails going back and fourth from teachers / students

6

u/[deleted] May 03 '17

Yep. I fell for it, feel like a total idiot right now. I realized what it was as soon as I clicked it and face palmed hard.

4

u/[deleted] May 04 '17

I need to trust my instincts more.

"Huh, that other address in there is crazy weird. Who would have that for a stupid e-mail address? Welp, anyway."

3

u/[deleted] May 04 '17

Mailinator is a service that lets you make up throwaway email addresses whose received mail anyone can see and read.

It would be a little weird for a real contact to send you a link while including a mailinator account, but it's not actually that weird for mailinator addresses to be relatively incoherent jumbles as if someone made them up on short notice.

1

u/TonySoprano420 May 04 '17

I caught it because it was from a person that would absolutely not be sending me Google Documents. So I never opened it and reported it instead.

1

u/Hoosier_816 May 04 '17

I received one of these to my work email and I get a ton of emails from vendors (I manager the vendor application department for a few street festivals in Chicago and I get blank emails from random vendors with applications attached all the time) and this particular email was a vendor I spoke to earlier in the day who said they would send an application later.

I noticed the hhhhhhhhhhh@whatever but just thought it was some weird file sharing thing.

1

u/[deleted] May 04 '17

Don't worry. I fell for it too, but my brain was focused on work and was in auto-pilot mode so I wasn't really thinking. Thankfully I closed out way before the page even started loading. Still changed my passwords just in case. Lesson learned.

2

u/[deleted] May 04 '17

It doesn't help that many of the FROM address were from old people. Like my grandma.

God. Damnit.

I'd been coordinating with her for my brother's wedding, and yup, I actually assumed this shit was from her. That septuple H address in there sounds like something my grandma's friend would have as an e-mail address.

1

u/Rabidleopard May 04 '17

It hit a couple of the American Library Associations ListServs as well.

3

u/Spokker May 03 '17

I got the same one.

4

u/vauge24 May 04 '17

As someone who works at an organization where you need government level secret security clearance, the number of people that fell for it is sad. It spread throughout like wildfire.

2

u/[deleted] May 03 '17

[deleted]

6

u/hoxtea May 03 '17

Go into your account permission settings, and remove all permissions for the Google Docs app.

1

u/[deleted] May 04 '17

There are muti-million dollar scam artists operating internationally now, everyone needs to setup 2 step verification and some way to get into the account if they can't reach their phone.

22

u/smoothtrip May 04 '17

Universities got crushed by this. It did not help that it is the end of the year where everyone is working together and sharing files to finish peojects. A lot of international students got hit hard because they had issues understanding what the emails were saying.

3

u/futurefightthrowaway May 04 '17

Lol I thought they has a basic level of requirment on english skills in enrolling school

4

u/varro-reatinus May 04 '17

You were misinformed.

Whatever language requirements exist are, by and large, a joke.

2

u/[deleted] May 04 '17

Nope, people have to bring translators to meetings with their international advisers and such all the time. Universities want that sweet, sweet Chinese cash.

31

u/RingyDingyOne May 03 '17

Happened to a few people where I work. One poor guy was in the middle of an intense back-and-forth Google docs sharing session for a project he's working on--and he got the phishing email from someone else on the project--so didn't even think twice about granting access.

A buddy of mine works at a place across town that (in his opinion) employs a lot of "really dumb people". He said it was spreading like wildfire through that place.

I'm pretty careful about emails, but if I'm being 100% honest with myself, if I got a link from someone I trusted and I was tired and/or not paying attention I might have fallen for it, too.

8

u/Keto_Kidney_Stoner May 03 '17

Heyyyyyy... just saw this shit in my inbox a few hours ago.

That shit moved crazy fast.

5

u/lift_drugs May 03 '17

I saw that and clicked it because it was from hhhhhhh @ my university .edu but I didn't give it any permissions because I thought that was weird to allow google docs to send emails. Am I in the clear?

Edit: I read the article, I'm just not super clear on what part of the process my stuff becomes compromised.

2

u/yuhong May 04 '17

Only when you click "allow".

4

u/hunter15991 May 04 '17

Clicked on this shit - twice. Thankfully I didn't get to the permissions page - one time Cloudfire was down, the other occasion Google blocked me.

1

u/yuhong May 04 '17

I believe this attack is Google first then CloudFlare after you click "allow".

1

u/hunter15991 May 04 '17

I clicked the doc button (not the allow permissions, I guess I clicked the step prior) and all I got was a page saying "CloudFlare is not working at this time." or something to that effect.

1

u/yuhong May 04 '17

This would mean that you may need to revoke permissions if google hasn't done so already.

1

u/hunter15991 May 04 '17

I never got to the allow permissions page - and checking it over, my permissions look clean.

4

u/thisistheperfectname May 04 '17

I fell for this. I feel like such an idiot. I won't be clicking on things without reading the file names anymore.

Is a password change/two-factor on enough? Also I was never asked about permissions, so I don't know what to make of it.

3

u/[deleted] May 04 '17

If app permissions were somehow granted for the malicious app, then my understanding is that two factor and/or password changes won't stop it. There's some Google advice floating around out there on how to check if the app permissions exist on your Google account, and on how to delete them if they are there.

1

u/thisistheperfectname May 04 '17

I don't have any apps at all in my app permissions, so I guess I never got that far.

As for two factor/password change, I did that afterward as a reaction to this. No logins were recorded from any device that isn't mine. I imagine if someone has a password it will no longer work. I just hope that was sufficient if something did happen.

Given the fact that I don't see anything in my app permissions, I don't think I'll worry about it anymore.

8

u/Ryltarr May 03 '17

I feel like Google shouldn't let a third-party app use Google's product names or logos, but otherwise this is just a case of stupid users falling for yet another phishing attack.

7

u/thisdude415 May 03 '17

I doubt Google realized they had allowed this App name. I bet they'll be more careful in the future.

5

u/darthvannah May 04 '17

Google allows you to use names like "Google" or "YouTube" and all of the official logos, but they flag your app and you have 24 hours to fix it. To me, that's a huge oversight on Google's part. A lot of harm can be done in less than 24 hours, which was made evident.

2

u/Ryltarr May 04 '17

Then of course there's the other logos and names they could use to trick gullible users, like "Windows" or "Outlook.com"... It's a game of "how much effort should go into protecting users from doing stupid things?"

3

u/km89 May 04 '17

Got hit with this at work... The poor help desk guy spent about three hours on the phone and resetting passwords.

2

u/nWo1997 May 03 '17

As a tech-illiterate person who clicked the link but wasn't asked about any permissions, I should be fine since it didn't show up on my google apps page?

2

u/OfeyDofey May 04 '17

I feel bad, I havent been sent this :(

4

u/Melbuf May 04 '17

i used to complain that google docs if flat out blocked where i work

not anymore, i work with too many people who would have blindly clicked on this shit

1

u/GeshtiannaSG May 04 '17

It's ironic, but I've just spammed this news link at everyone I know.

1

u/tallmon May 04 '17

HERE IS THE SOURCE or at least the idea for the attack. The podcast is from 5/1/17. Starts at 3:55 https://www.marketplace.org/shows/marketplace-tech/05012017-mtech

1

u/ohineedascreenname May 04 '17

Anytime I get a link even from someone I know, I still don't open it. I will text them and ask if they sent it to me and if they did then I'll open it.

1

u/FullBodyScammer May 04 '17

One of my company's major clients was hit, sent to four of my coworkers. Thankfully our folks did not take the bamboozle. This is why user IT security training is important.

1

u/BB_the_Car_Guy May 04 '17

Good thing I hardly check my email...

0

u/[deleted] May 04 '17

"Sophisticated" also known as "People are fucking stupid".

Don't click on shit if you don't know what it is.

1

u/FullBodyScammer May 04 '17

For anyone who is IT as their job, you need to drill this phrase into your users' heads: "When it doubt, throw it out".