- Get link
- X
- Other Apps
- Get link
- X
- Other Apps
Ever on the lookout for a new avenue of attack,
cybercriminals had figured out a method of using Google App Scripts to
automatically download malware hosted in Google drive to any computer.
Google App Scripts, the JavaScript development platform used
to create stand-alone apps with extensions to the Google Apps SaaS system, has an automatic document
sharing capability that could be perverted to download various types of malware
and the social engineering systems needed to convince targets turn on the
malware. The cybersecurity firm's researchers noted that while Google was told
of and fixed the vulnerabilities there remains the threat that this type of
attack could become more prevalent than those using malicious Microsoft Word
macros.
The first step was to upload malware executables to Google
Drive to which hackers could create a public link. Step two has the bad guys
sharing a Google Doc linked to the malware with their intended victims with a
note to convince the recipient to open the doc. This is essentially a
document-based phishing attack.
“While we frequently observe Google Docs phishing and
malware distribution via links to Google Drive URLs, extensible SaaS platforms
allow greater degrees of sophistication, malware propagation, and automation
that are also much more difficult to detect,” Proof point said.
Using a SaaS application like Google Drive
creates an entirely new attack surface that business and consumers need to
guard. Because this is relatively new most workers might not realize a Google
doc holds any potential danger, but on the bright side the fact that the same
defensive measures used to prevent email-based phishing will also work against
this type of attack, Proof point said.
On the downside, the fact that SaaS application
attacks are much easier for hackers to assemble, compared to those using
macros, probably means this methodology will be used more often in the future
and spread from Google Drive to others like Office 365, G-Suite and Box.
- Get link
- X
- Other Apps
Comments
wonderful post! Thank you for sharing this infowith us.keep updating imwould like to know more
ReplyDeleteupdates on this topic very useful context I would i like to suggest this blog to my friend.
Cloud computing course in Chennai
cloud computing training
Yeah.. Good content.. Hoping for more info like this.. 😊
DeleteVery useful information to everyone thanks for sharing, learn the latest updated Technology at Best Training institutions
ReplyDeleteSalesforce Lightning is the latest updated technology
projects Training
Salesforce Online Training in Bangalore