Why India is not suitable for self driving cars.

PHISHING ATTACKS OVER CLOUD-BASED DOCS





Ever on the lookout for a new avenue of attack, cybercriminals had figured out a method of using Google App Scripts to automatically download malware hosted in Google drive to any computer.
Google App Scripts, the JavaScript development platform used to create stand-alone apps with extensions to the Google Apps SaaS system, has an automatic document sharing capability that could be perverted to download various types of malware and the social engineering systems needed to convince targets turn on the malware. The cybersecurity firm's researchers noted that while Google was told of and fixed the vulnerabilities there remains the threat that this type of attack could become more prevalent than those using malicious Microsoft Word macros.

The first step was to upload malware executables to Google Drive to which hackers could create a public link. Step two has the bad guys sharing a Google Doc linked to the malware with their intended victims with a note to convince the recipient to open the doc. This is essentially a document-based phishing attack.
“While we frequently observe Google Docs phishing and malware distribution via links to Google Drive URLs, extensible SaaS platforms allow greater degrees of sophistication, malware propagation, and automation that are also much more difficult to detect,” Proof point said.

Using a SaaS application like Google Drive creates an entirely new attack surface that business and consumers need to guard. Because this is relatively new most workers might not realize a Google doc holds any potential danger, but on the bright side the fact that the same defensive measures used to prevent email-based phishing will also work against this type of attack, Proof point said.
On the downside, the fact that SaaS application attacks are much easier for hackers to assemble, compared to those using macros, probably means this methodology will be used more often in the future and spread from Google Drive to others like Office 365, G-Suite and Box.


Comments

  1. wonderful post! Thank you for sharing this infowith us.keep updating imwould like to know more
    updates on this topic very useful context I would i like to suggest this blog to my friend.

    Cloud computing course in Chennai
    cloud computing training

    ReplyDelete
    Replies
    1. Yeah.. Good content.. Hoping for more info like this.. 😊

      Delete
  2. Very useful information to everyone thanks for sharing, learn the latest updated Technology at Best Training institutions
    Salesforce Lightning is the latest updated technology
    projects Training
    Salesforce Online Training in Bangalore

    ReplyDelete

Post a Comment