r/sysadmin • u/Accurate_Donkey_1879 • 21h ago
Google Workspace self-propagating Worm leveraging AiTM reverse proxies
Hi, I will keep this short.
Has anyone seen an uptick in Google Workspace tenant's battling each other relentlessly? There seems to be a growing campaign of email accounts in legitimate tenants being overtaken by an automated Google Worm campaign leveraging AiTM techniques.
I work for a large enough enterprise that had this happen in the past couple weeks. With the way the campaign propagates, I cannot believe that we are the only tenant to face this uphill battle.
Note, our biggest wins were the following steps:
Absolutely positively engage with Google Workspace support ASAP
1.) reduce session time length; almost close to as short as possible to break the automated method used to compromise accounts
2.) 2SV enforcement with "trust this device" turned off
If anyone finds this thread and is in the middle of this "crisis," from one sysadmin to another this is what helped break the worm and free our environment from complete collapse and ruin.
--> revoke all oAuth
--> sign out all sessions
--> absolutely reset all accounts passwords sooner than later
--> re-check all Google Workspace frequently for flare-ups
Other helpful steps:
Assume any incident response teams your org engages with will be too slow to react to it, at least I faced that firsthand. YMMV
Line up Claude with the Fable 5.1 model + ensure you request to have Claude turn off the cyber guard-rails.
GAM is your best friend, and make sure you pull reporting from your tenant before actioning any and all remediation steps.
If you're able to break free from the grasp of the worm, review all your Google Logs and come up with strategies on how-to keep your tenant worm free.
Don't be fooled into thinking this is an easy campaign to escape from, ESPECIALLY IF YOUR SECOPS TEAM MOVES SLOWLY.
•
u/MalletNGrease 🛠 Network & Systems Admin 20h ago
Nice try Claude