Remove tag docs
article thumbnail

Attackers use Google Calendar RAT to abuse Calendar service as C2 infrastructure

Security Affairs

” Google TAG has previously observed threat actors abusing Google services in their operations. In March 2023, TAG spotted an Iran-linked APT group using macro docs to infect users with a small.NET backdoor, BANANAMAIL that relies on Gmail as C2 infrastructure.

article thumbnail

Google takes on Docs notification spammers

Malwarebytes

One such Google Docs revamp is the “tag tool” which fetches lists of recommended people. Around October 2020, spam messages via Google Docs came to light. It’s worth noting this behaviour wasn’t just restricted to Docs; other apps like Slides were affected too. So far, so good. Specifically: the comments feature.

Risk 71
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Attackers create phishing lures with standard tools in Google Docs to steal credentials

SC Magazine

Researchers on Thursday reported that hackers are using standard tools within Google Docs/Drive to lead unsuspecting victims to fraudulent websites, stealing credentials in the process. The attacker does not need the iframe tags and only needs to copy the part with the Google Docs link. brionv, CC BY-SA 2.0

Phishing 110
article thumbnail

Surveillance firm’s leaked docs show the purchase of an $8M iOS RCE zero-day exploit?

Security Affairs

In June, researchers from Google’s Threat Analysis Group (TAG) revealed that the Italian surveillance firm RCS Labs was helped by some Internet service providers (ISPs) in Italy and Kazakhstan to infect Android and iOS users with their spyware. Follow me on Twitter: @securityaffairs and Facebook. Pierluigi Paganini.

article thumbnail

Google files lawsuit against blockchain botnet operators

CyberSecurity Insiders

As per the Threat Analysis Group (TAG) of Google, the criminals are using such compromised devices to mine cryptocurrency, steal credentials from victims, and use them as proxies to hide their attacks.

article thumbnail

Google disrupts the Glupteba botnet

Security Affairs

.” Google announced to have removed around 63 million Google Docs files used as part of the Glupteba operation to distribute the bot to the victims. Glupteba disruption over last year: 63M Google Docs 1,183 Google Accounts, 908 Cloud Projects, and 870 Google Ads accounts. users were warned via Safe Browsing.

Backups 114
article thumbnail

Ingenious Phishing Tactics in the Modern Scammer's Toolbox

SecureWorld News

The catch was that the document contained a function to transform these gibberish-looking symbols into hexadecimal values that denoted specific JavaScript tags. Google Docs comments abused to spread toxic links In early January 2022, bad actors mastered a new unusual technique to spew out phishing links and avoid detection.