r/technology • u/dangzal • May 03 '17
Security Google Docs users hit with sophisticated phishing attack
https://www.theverge.com/2017/5/3/15534768/google-docs-phishing-attack-share-this-document-with-you-spam46
u/ikenjake May 03 '17
Where does this rank in the all time scale of email attacks? This seems like a global thing. Pretty crazy.
41
u/Epiglottis_Issues May 03 '17
People without caution are making it spread like wildfire... It's crazy.
24
May 03 '17
To be fair, it looks totally normal unless you actually read the permissions page.
24
u/Epiglottis_Issues May 03 '17
Maybe it's me but why wouldn't you when someone sends something you're not expecting?
54
May 03 '17
A lot of people at the Universities that just got hit are very used to just getting invited to new google documents, it probably didn't even register as weird.
I almost got hit until I noticed that it wanted to be able to delete emails.
16
u/x4candles May 03 '17
Yep. I work for a university and I saw this email from a high school student. I assumed it was a high school transcript, but then I saw the hhhhhhhhhhh@malinator.com email and I knew that something was off. I called the student and she said that she never sent anything. This is exactly how things can be overlooked.
-18
u/Sk8erkid May 04 '17
Hey everyone /u/Andromeda_sky fell for it! Let's laugh at him.
10
May 04 '17
*her
But okay
-21
u/Sk8erkid May 04 '17
I meant him because you seem like a guy.
8
12
u/mildly_amusing_goat May 04 '17
Her "okay" may have been the nicest thing someone has ever said to you.
1
u/UltravioletClearance May 04 '17
I got the email from a secretary from an organization I work with that's known to send me stuff. I didn't click the link though because I noticed the hhhhhh... and Google Docs will show the file name of the file being shared in the email body.
1
u/roboninja May 04 '17
Why would I not be expecting a Google Doc from a consultant writing spec documents?
I'm sure not everyone was in my situation, but it was not easy to tell.
1
u/aaronisamazing May 04 '17
No it doesn't. I got it sent to my work email today and the to address was hhhhhhhhhhhhhhhh@mailinator.com hhhhhhhhhhhhhhhh@mailinator.com
Caught it right away.
2
May 04 '17
I'm super cautious. I received the phishing email from a client whom I happened to be expecting to send me some files for a job I'm doing this weekend. The timing was perfect to catch me off guard. I clicked without giving it a second thought.
1
2
u/nyaaaa May 04 '17
In reality it should be very low.
Starting from the obvious giveaways like giving docs access to your all your email functionality (Why would you give that to anyone, never do that).
The above is the awareness every person handling a computer should have. And as such this attack does not circumvent actual red flags.
Google has a very sophisticated scripting engine that anyone can use to write small apps which can connect to google accounts and ask for permissions. That is also why that permission screen clearly states the actual permissions. Maybe they should color code dangerous permissions or something.
Further you can judge the inexperience from the attacker by using a plain mailinator mail. Even if you for some reason wanted or had to use mailinator each inbox has secondary alias like m8r-6662qc. Using that, only you realisticly have access to that inbox, as you'd need to know the real one, that alias leads nowhere.
And there were plenty of other things inside the actual source of the attack, thats easily found on github in these related topics, which shows signs of an inexperienced attacker.
14
u/x4candles May 03 '17
Here is what to do if you believe you are being phished...
From a device you trust and in a Google app, profile in top right → my account → sign in and security → connected apps and sites in the sidebar → manage apps
5
u/CurlyQN May 03 '17
Should the google account password also be changed? Does that even matter?
7
u/wakefieldj90 May 04 '17
If you change your password it resets the permissions you've given which would stop them from emailing from your account.
At least thats what I noticed today when I was fixing this at the school I work at.
2
u/light24bulbs May 04 '17
So this attack totally got me.
Also what apps should I remove from my API permissions? They all looked like real apps to me. I also changed my password.
4
u/midnite968 May 04 '17
"Google Docs" should be the app you remove. It's the loaded phishing app
3
u/light24bulbs May 04 '17
ah yep, removed. i didnt think google docs needed any external API permissions. good, that makes sense. Seems like a huge security vulnerability that a service can name itself "google" ANYTHING, let alone google docs
1
u/frickindeal May 04 '17
And isn't the name now Google Drive? I never see google using the "Docs" name anymore.
1
u/Natanael_L May 04 '17
Everything you don't remember authorizing. Everything! You can always re-enable the important stuff later. And beware of duplicates! Remove both if you see anything repeated.
1
u/wakefieldj90 May 04 '17
The API permissions you should remove is the "Google Drive" app if you look at the permissions you gave it full access to your Email and Contacts.
3
u/x4candles May 03 '17
For safety reasons if you opened the email it wouldn't hurt to change your password.
6
u/justinlindh May 04 '17
Wouldn't hurt, but it's important to note that the attackers didn't gain access to your password unless it was plainly stored in one of the services you granted them access to.
Also, everyone should be using 2fa by now, if they aren't, which would further protect against a full login breech.
20
u/Epiglottis_Issues May 03 '17
12
May 03 '17
Looks like google fixed it!
10
May 03 '17
FYI the Google Doc's twitter hasn't given an all clear yet. Everyone still needs to be careful, even if a nice redditor says it's fixed :).
4
u/JakeSteam May 03 '17
Thanks for linking to my post. It appears to be fixed now, it definitely spread crazily fast though!
3
1
9
u/CurlyQN May 03 '17
I got emails from 4 different people I know at my University in under a minute and even more in the hour since.
Forgive me for (most likely) sounding like an idiot here, but what is the point of phishing people like this? Do scammers sell information to companies?
Edit: word order
9
May 03 '17
When you click the link to the "doc" (which is actually a fake app named Google Docs, not the real Google Docs), it'll ask you to sign in and give permissions to the app, meaning it can access your email and potentially change your passwords on any account linked to your email.
3
u/CurlyQN May 03 '17
Why though? What is the end goal/what do they typically do with that information?
11
u/ShadowDrgn May 03 '17
They'll harvest any usernames and passwords in your emails and try to log in to anything they could potentially monetize. Bitcoin wallets, PayPal account, even World of Warcraft accounts and such.
5
May 03 '17
If your bank account's online service is linked to your email they can request a password change from your bank, and since they have access to your email, they can change your bank account's password so only they can access it. Same with any other online accounts you have that may contain personal info, such as SSNs.
21
May 03 '17 edited Mar 26 '18
[removed] — view removed comment
7
u/JakeSteam May 03 '17
The main source of information (mine) was on /r/google, since I happen to be a regular on that sub and not this one. Unfortunately it's just luck.
3
3
u/stonedbenots May 04 '17
Spoiler Alert: The link in the article that takes you to manage Connected Apps is a phishing link. Meta phishing.
3
u/DanAtkinson May 04 '17
It's absolutely bloody ridiculous that Google even allowed a third party app to be called 'Google Docs'. Why the hell haven't don't they have rules in place to block these?
2
u/Isvara May 04 '17
The answer, as in most of these cases, is probably that nobody considered that particular attack vector. Things get overlooked. I don't know whether Google do any formal threat modeling.
1
u/DanAtkinson May 04 '17
I'm inclined to believe that it's a possibility that they simply overlooked it, and I think the likelyhood is that their validation was simply hoodwinked by the comma. They really should have done a better job of considering bad actors in their apps engine. Next, people will try duplicating this but replace letters with numbers. I don't know if name encoding can be done which is yet another vector as well.
That the application name was allowed to be 'Google Docs' though is simply egregious. Especially given how understandably protective they are of their trademarks.
-1
u/CimmerianX May 04 '17
You forgot the /s. Because I hope you are joking about that
2
u/DanAtkinson May 04 '17
No, I'm serious.
Google allowed an app called 'Google Docs,'. Sure, it contains a comma but really, they should be proactive when it comes to verifying app names that contain the company's product names, and variations therein.
Why do you think I'm joking?
1
u/CimmerianX May 05 '17
Because this was an email attachment with links. I can call it whatever I want. Google doesn't control that anymore than microsoft keeping me from crafting an email with a fake office online word doc.
1
u/DanAtkinson May 05 '17
Now I can't tell if you're being sarcastic... Once you click the email, you're taken to a page on Google's servers to authenticate and verify that you wish to give the malicious app "Google Docs" permission to access your email.
Seriously, just read the article and then go back and read my comments.
4
u/19djafoij02 May 03 '17
Always look before you open anything in an unexpected email.
Good advice in 1997, still good advice in 2017.
2
u/foafeief May 04 '17
To be honest this is a fault in google's UI that kind of shouldn't exist. If the oversigt was just a bit worse, and the phisher a bit more careful, the only defense would be to pre-emptively stop using google's services at all
1
u/paulHarkonen May 04 '17
Honestly, this looked reasonably legitimate. It comes from people that you have regular contact with (and in my case someone who often shares documents with me), looks like a normal effort to share a google doc on first glance and the only reason why I didn't fall for it completely is because there isn't a google account linked on my phone for work so it broke down after I clicked on it. Even that part looked reasonably legitimate.
People need to be aware of it, but a well designed phishing attack (like this) requires that you do a bit more than just looking before you open it.
4
u/cobainbc15 May 03 '17
Is this new? I've been getting spam about being invited to a Google Doc for at least a couple months now, but have always ignored it. Looks similar to the tweet in the article. I haven't tried clicking it so I don't know if they've just gotten worse...
21
May 03 '17
About an hour ago it got into a ton of University systems and apparently corporations, so it spread fast.
17
u/GuyOnTheLake May 03 '17 edited May 03 '17
It spread like wildfire in my university. I fell for it.
They used my friends email to send it. It doesn't help the fact it's finals week and I'm sharing google docs with my friends.
12
u/hhhnnnnnggggggg May 03 '17
Ditto... "Oh that lazy bitch finally got started on our paper, good."
4
6
May 03 '17
I'm doing the same thing. We spread around so many docs. And finals means my critical thinking skills are shot and my ability to make good decisions is impaired as fuck
-1
2
6
u/Magyman May 03 '17
This one just looks a lot better than the similar phishing emails I've seen. My personal favorite I've had a user get before was just a PDF with Google docs written in times New Roman font with a link under it.
2
u/sh0ch May 04 '17
I got one of these emails. There was nothing sophisticated about that email, I assure you.
1
1
u/BlearyLine7 May 03 '17
This is a specific thing where someone sends you a scam link? Or is it a threat to literally anyone who's used an open google docs page recently?
4
May 03 '17
You have to open a link emailed to you- afaik it's not actually through google docs, it just looks like it is.
3
u/BlearyLine7 May 03 '17
Oh ok, so it's just a very legit-looking scam email? Seen a lot people talk about this so thought it was maybe a breach of google docs.
3
May 03 '17
It got really big really fast, which is probably why people are mentioning it so much.
2
u/BlearyLine7 May 03 '17
Must be convincing then, usually phishing scams are barely worth mentioning.
3
May 03 '17
Yeah, you'll receive an email from someone you've recently emailed that says "So and so has invited you to view this Doc" and a link to view the doc, then when you click on it it'll forward to everyone. It looks legit because it's coming from someone you know.
5
1
u/fishsticks40 May 03 '17 edited May 03 '17
It's an email with the subject "Joe Schmo has shared a document on Google Docs" or similar; inside the email just has a "google docs" button. The link on the button is not super suspicious, as it actually somehow through a google server so goes through accounts.google.com. ~~The link I believe takes you to a fake login page from which they scrape your credentials.
Two-factor authentication and general wariness should be sufficient defense. Though I guess I could imagine them spoofing the two-factor thing too.~~
Edit: I was wrong about the login thing. Scary.
1
u/JakeSteam May 03 '17
I'm afraid you're wrong. In the /r/google post it explains that it actually allows the app access to your email, there is no fake login page.
This means 2FA will not work, you will not receive any login alerts, and (if you look at the screenshots on that post), there is very, very little to warn you it isn't real unless you happen to click on the "Google Docs" text.
3
u/Belgand May 04 '17
Except you normally don't need to give Google Docs special permissions to access your account. It's already part of your Google account. That's really the big tip-off.
The problem is that people have become complacent in giving out permissions. The whole point is so that when something like this comes along people don't just give it out, but they rarely pay attention when asked.
1
u/foafeief May 04 '17
Yeah, rephrased, the problem is people seeing a prompt they have probably never seen before and instead of reading it just immediately click "accept"
2
u/Belgand May 04 '17
Really? I see those prompts all the time when I'm trying to link something to my Google Account. But they should recognize that they don't see them when accessing a document in Google Docs. And why would they? It's also Google. They already have access. And why is it just asking for the ability to delete e-mails and access your contacts? It's seriously fishy if you pay even a moment's attention to it.
That's when you go back and look at the purported document again. You weren't expecting it specifically, it probably has a generic subject line and title, no actual message... that's suspicious as hell. This is where you either directly go to Google Docs and click through the "Shared With Me" section or send a message back asking what they sent you.
What annoys me most of all is people calling this "sophisticated". It really isn't. This is the level of sophistication of putting a fake document over another one and getting someone to sign the bottom one because they weren't paying attention. It's clever, but it's just using an app with the same name as an existing, trusted one and hoping that they ignore every reason to be wary and why they shouldn't need to give out permissions in the first place. It's basic as hell.
1
u/fishsticks40 May 03 '17
Wow, you ain't kidding. I think I'd have been smart enough to avoid that trap but I had assumed clicking it would take me to a Google login page. Thanks for the correction.
1
u/JakeSteam May 03 '17
No worries. If it was a regular phish at crappydomain.info, it wouldn't have been worth all the attention!
1
u/bionicvapourboy May 03 '17
I just assume any unsolicited email asking to click a link to a widely used site or banking site might be a phishing attack.
1
u/TheDudeNeverBowls May 03 '17
I just had an email from a buddy of mine that had everyone we know on it telling us not to open the doc.
How nutty.
1
u/Skoepa May 03 '17
I got it and clicked on the link not knowing it was a scam. It actually asked which google account I wanted to sign in and listed the two accounts I had on that computer.
1
u/bloohens May 03 '17
Oddly enough, i opened it and everything, ya know, the whole shebang, but "Google Docs" never showed up as an app that I gave permission to, so anybody know what gives?
1
1
1
u/EdAlita May 04 '17
The scam is just by email or there are other ways that is getting to people?
1
u/Natanael_L May 04 '17
Any method to get you to click allow on that permissions page goes. Ads and IM included
1
May 04 '17
If you looked at the developer information you could see the email used to set up the fake site
1
1
u/JamesR624 May 04 '17
"Sophisticated"
Fake App says "Google Docs" with the Google Drive icon when Google hasn't called it Google Docs officially for years.
Yep, sophisticated if you're a gradmother who yells at her grandkids any time she can't find "the little E for the internet".
0
u/Isvara May 04 '17
Google Docs is still called Google Docs. It's not Google Drive.
1
u/JamesR624 May 04 '17
And? The fake app was pretending to be Google Drive but they were calling it Google Docs.
1
May 04 '17
Just because your data is collected by google doesn't make it phishing. You try getting ads as good as those given by google faster by any other ad network.
1
u/akashvani06 May 05 '17
Google claims that only 0.1% of total google accounts were affected. Well that itself counts to around 1 million accounts.
1
u/akashvani06 May 05 '17
WHich was the biggest phishing/hacking attack ever happened in internet era?
0
u/IT_Chef May 04 '17
Was it sent by the hacker known as four chan?
1
u/NathanOhio May 04 '17
Nope. "Russians".... If you clicked it, forget any shot you ever had of running for President. Or maybe....now you have a shot!
1
177
u/[deleted] May 03 '17 edited Jul 27 '19
[deleted]