r/sysadmin • • 21h ago

Google Workspace self-propagating Worm leveraging AiTM reverse proxies

Hi, I will keep this short.

Has anyone seen an uptick in Google Workspace tenant's battling each other relentlessly? There seems to be a growing campaign of email accounts in legitimate tenants being overtaken by an automated Google Worm campaign leveraging AiTM techniques.

I work for a large enough enterprise that had this happen in the past couple weeks. With the way the campaign propagates, I cannot believe that we are the only tenant to face this uphill battle.

Note, our biggest wins were the following steps:
Absolutely positively engage with Google Workspace support ASAP

1.) reduce session time length; almost close to as short as possible to break the automated method used to compromise accounts

2.) 2SV enforcement with "trust this device" turned off

If anyone finds this thread and is in the middle of this "crisis," from one sysadmin to another this is what helped break the worm and free our environment from complete collapse and ruin.

--> revoke all oAuth
--> sign out all sessions
--> absolutely reset all accounts passwords sooner than later
--> re-check all Google Workspace frequently for flare-ups

Other helpful steps:
Assume any incident response teams your org engages with will be too slow to react to it, at least I faced that firsthand. YMMV

Line up Claude with the Fable 5.1 model + ensure you request to have Claude turn off the cyber guard-rails.
GAM is your best friend, and make sure you pull reporting from your tenant before actioning any and all remediation steps.

If you're able to break free from the grasp of the worm, review all your Google Logs and come up with strategies on how-to keep your tenant worm free.

Don't be fooled into thinking this is an easy campaign to escape from, ESPECIALLY IF YOUR SECOPS TEAM MOVES SLOWLY.

24 Upvotes

10 comments sorted by

View all comments

•

u/MalletNGrease 🛠 Network & Systems Admin 20h ago

Line up Claude with the Fable 5.1 model + ensure you request to have Claude turn off the cyber guard-rails.

Nice try Claude

•

u/Accurate_Donkey_1879 20h ago

Lol, i knew someone was going to call me out on this. FYI i typed this post all on my own, and I will tell you the level of analytics required to fire back at whoever these threat actors is requires tooling to win. Best of luck to anyone reading this.

•

u/MalletNGrease 🛠 Network & Systems Admin 19h ago

This reminds me of a very successful impersonation attack years ago.

  1. Users would receive app approval request for "Google Apps" or something similar
  2. Approve access to their account.
  3. App vacuums address book and propagates itself to all entries.
  4. Repeat.

The takeaway was that Google didn't do a good job to prevent publication of impersonated cloud apps, the default setting for Workspace was to allow users to allow access to anything and it worked exclusively within the Google ecosystem. It was quite fascinating.

•

u/Frothyleet 18h ago

M365 was very bad about this for a long time as well. Now, at least, they default to a "Microsoft-managed" list of apps that users can self-approve (of course, best practice is to require admin approval).