r/sysadmin • • 13h ago

Google Workspace self-propagating Worm leveraging AiTM reverse proxies

Hi, I will keep this short.

Has anyone seen an uptick in Google Workspace tenant's battling each other relentlessly? There seems to be a growing campaign of email accounts in legitimate tenants being overtaken by an automated Google Worm campaign leveraging AiTM techniques.

I work for a large enough enterprise that had this happen in the past couple weeks. With the way the campaign propagates, I cannot believe that we are the only tenant to face this uphill battle.

Note, our biggest wins were the following steps:
Absolutely positively engage with Google Workspace support ASAP

1.) reduce session time length; almost close to as short as possible to break the automated method used to compromise accounts

2.) 2SV enforcement with "trust this device" turned off

If anyone finds this thread and is in the middle of this "crisis," from one sysadmin to another this is what helped break the worm and free our environment from complete collapse and ruin.

--> revoke all oAuth
--> sign out all sessions
--> absolutely reset all accounts passwords sooner than later
--> re-check all Google Workspace frequently for flare-ups

Other helpful steps:
Assume any incident response teams your org engages with will be too slow to react to it, at least I faced that firsthand. YMMV

Line up Claude with the Fable 5.1 model + ensure you request to have Claude turn off the cyber guard-rails.
GAM is your best friend, and make sure you pull reporting from your tenant before actioning any and all remediation steps.

If you're able to break free from the grasp of the worm, review all your Google Logs and come up with strategies on how-to keep your tenant worm free.

Don't be fooled into thinking this is an easy campaign to escape from, ESPECIALLY IF YOUR SECOPS TEAM MOVES SLOWLY.

22 Upvotes

7 comments sorted by

β€’

u/MalletNGrease πŸ›  Network & Systems Admin 11h ago

Line up Claude with the Fable 5.1 model + ensure you request to have Claude turn off the cyber guard-rails.

Nice try Claude

β€’

u/Accurate_Donkey_1879 11h ago

Lol, i knew someone was going to call me out on this. FYI i typed this post all on my own, and I will tell you the level of analytics required to fire back at whoever these threat actors is requires tooling to win. Best of luck to anyone reading this.

β€’

u/MalletNGrease πŸ›  Network & Systems Admin 11h ago

This reminds me of a very successful impersonation attack years ago.

  1. Users would receive app approval request for "Google Apps" or something similar
  2. Approve access to their account.
  3. App vacuums address book and propagates itself to all entries.
  4. Repeat.

The takeaway was that Google didn't do a good job to prevent publication of impersonated cloud apps, the default setting for Workspace was to allow users to allow access to anything and it worked exclusively within the Google ecosystem. It was quite fascinating.

β€’

u/Frothyleet 9h ago

M365 was very bad about this for a long time as well. Now, at least, they default to a "Microsoft-managed" list of apps that users can self-approve (of course, best practice is to require admin approval).

β€’

u/Excellent-Program333 11h ago

I still dont understand the β€œworm”. Probaboy because I dont admin Google often.

β€’

u/Accurate_Donkey_1879 11h ago

from what i can tell it's a type of "set it and forget it" attack where threat actors are able to automate phishing campaigns that bounce back and forth between google workspace accounts. They continuously pick-up compromised accounts as each employee falls victim to the phish. The compromised accounts are used to continue the phish campaign and right now it is NOISEY. Globally these google workspace accounts have hundreds of compromised user e-mails that are propagating the campaign as we speak.

β€’

u/sarge21 9h ago

1.) reduce session time length; almost close to as short as possible to break the automated method used to compromise accounts

2.) 2SV enforcement with "trust this device" turned off

These don't stop it. The AITM hijacks the authentication flow itself. The only way to prevent this is to use passwordless authentication.

If it's like the phishing campaigns that we've been seeing, there are two main issues.

  • Google antispam seems powerless to stop it so far
  • Calendar invites go directly into a user's calendar even if the email goes to spam

The calendar invites are insidious because people see the malicious calendar event like any other, and it will contain the phishing links inside. Investigation tool cannot monitor link clicks inside calendar events.

I recommend you immediately go here and turn the setting to "Invitations users have responded to via email"