GOOGLE DRIVE PHISHING SCAM
11/03/2020

Google Drive has become a new lure for scammers to phish unaware victims. A flaw in Google Drive is being exploited to send out seemingly legitimate emails and push notifications from Google that, if opened, redirects to malicious websites.

OVERVIEW

  • A flaw in Google Drive is being exploited by scammers to send out seemingly legitimate emails and push notifications from Google that, if opened, could redirects victim to malicious websites.

  • The smartest part of the scam is that the emails and notifications it generates come directly from Google.

  • The scammer uses the collaboration feature in Google Drive of mobile device to generate a push notification inviting people to collaborate on a document.

 

Google