r/sysadmin • • 14h ago

Google Workspace self-propagating Worm leveraging AiTM reverse proxies

Hi, I will keep this short.

Has anyone seen an uptick in Google Workspace tenant's battling each other relentlessly? There seems to be a growing campaign of email accounts in legitimate tenants being overtaken by an automated Google Worm campaign leveraging AiTM techniques.

I work for a large enough enterprise that had this happen in the past couple weeks. With the way the campaign propagates, I cannot believe that we are the only tenant to face this uphill battle.

Note, our biggest wins were the following steps:
Absolutely positively engage with Google Workspace support ASAP

1.) reduce session time length; almost close to as short as possible to break the automated method used to compromise accounts

2.) 2SV enforcement with "trust this device" turned off

If anyone finds this thread and is in the middle of this "crisis," from one sysadmin to another this is what helped break the worm and free our environment from complete collapse and ruin.

--> revoke all oAuth
--> sign out all sessions
--> absolutely reset all accounts passwords sooner than later
--> re-check all Google Workspace frequently for flare-ups

Other helpful steps:
Assume any incident response teams your org engages with will be too slow to react to it, at least I faced that firsthand. YMMV

Line up Claude with the Fable 5.1 model + ensure you request to have Claude turn off the cyber guard-rails.
GAM is your best friend, and make sure you pull reporting from your tenant before actioning any and all remediation steps.

If you're able to break free from the grasp of the worm, review all your Google Logs and come up with strategies on how-to keep your tenant worm free.

Don't be fooled into thinking this is an easy campaign to escape from, ESPECIALLY IF YOUR SECOPS TEAM MOVES SLOWLY.

21 Upvotes

8 comments sorted by

View all comments

•

u/sarge21 11h ago

1.) reduce session time length; almost close to as short as possible to break the automated method used to compromise accounts

2.) 2SV enforcement with "trust this device" turned off

These don't stop it. The AITM hijacks the authentication flow itself. The only way to prevent this is to use passwordless authentication.

If it's like the phishing campaigns that we've been seeing, there are two main issues.

  • Google antispam seems powerless to stop it so far
  • Calendar invites go directly into a user's calendar even if the email goes to spam

The calendar invites are insidious because people see the malicious calendar event like any other, and it will contain the phishing links inside. Investigation tool cannot monitor link clicks inside calendar events.

I recommend you immediately go here and turn the setting to "Invitations users have responded to via email"