New phishing campaign targets Gmail users
Gmail

Phishing campaign targets Gmail users

An attack on your computer could start with something as simple as ignoring the URL of the page you're visiting. If that address was actually a link inside a PDF file or an email, it can lead you to portals specially prepared to steal credentials via phishing, and in recent weeks a campaign focused on Gmail users has been detected. A small subtlety in the address bar and a good use of elements like headers and attachments allowed this campaign to achieve a level of effectiveness that surprises novices and experts alike.

Losing your credentials to a malicious element is one of the worst things that can happen to you. The risk is much greater than we estimate simply because it's not just one service that's compromised. Take Google's case. A standard account gives access to essentially all the resources Mountain View offers, including Gmail, Google Drive, Google Docs, Blogger, YouTube, AdWords, AdSense, the Android Play Store... I think you get the idea. The latest specimen prioritizes Gmail users, and its story begins with an email supposedly sent by one of your contacts...

New phishing campaign targets Gmail users

A fake email has characteristics that allow its quick identification, starting with wide differences in language and spelling mistakes. However, according to reports, this attack can send emails with legitimate headers and attachments that were used during a previous communication between both users. If you try to click on the attachment preview, you'll be taken to what appears to be the main Gmail login page. The problem is that there's a hidden trap, and it's right in the address bar. The string doesn't start with the expected "https://accounts.google.com", but rather with a small "data:text/html," before it. In reality, that's the beginning of a long text structure that transmits your credentials to the attacker, and once they have them, they repeat the whole process with the rest of your contacts.

How to protect yourself

Fortunately, protecting yourself from this campaign isn't very complicated. The first step is obviously to observe the URL closely. If you don't find the "https://" at the front in Gmail (or any other Google login portal) with its corresponding padlock or green label and the certificate's auxiliary data, something is wrong. Two-step verification is another useful resource, although there's a remote possibility that the phishing site could be modified to also request the verification code (the attack would need to be almost real-time). The safest option (for now) would be the use of physical keys, as Google has been suggesting for a while. Finally, it's not a bad idea to check the activity logs in Gmail. If something out of place appears in them, it's recommended to change your password immediately.

(Note from the editor: Google recognized the potential of this attack and confirmed that it's working on additional security measures that will be available with Chrome 56. We imagine that Mozilla will follow a similar path.)

More information: