Google blocked 1.6 mn phishing emails since May 2021

by IANS |

San Francisco, Oct 21 (IANS) Tech giant Google has blocked 1.6 million phishing emails Since May 2021, which were part of a malware campaign aimed at stealing YouTube accounts and promoting cryptocurrency schemes.

According to Google's Threat Analysis Group, in collaboration with YouTube, Gmail, Trust and Safety, CyberCrime Investigation Group and Safe Browsing teams, Google's protections have decreased the volume of related phishing emails on Gmail by 99.6 per cent.

"We blocked 1.6M messages to targets, displayed 62K Safe Browsing phishing page warnings, blocked 2.4K files and successfully restored 4K accounts," the company said in a blog post.

"With increased detection efforts, we have observed attackers shifting away from Gmail to other email providers (mostly email.cz, seznam.cz, post.cz and aol.com)," it added.

According to the report, the group tracks actors involved in disinformation campaigns, government backed hacking, and financially motivated abuse.

"Since late 2019, our team has disrupted financially motivated phishing campaigns targeting YouTubers with Cookie Theft malware," the company said.

"The actors behind this campaign, which we attribute to a group of hackers recruited in a Russian-speaking forum, lure their target with fake collaboration opportunities (typically a demo for anti-virus software, VPN, music players, photo editing or online games), hijack their channel, then either sell it to the highest bidder or use it to broadcast cryptocurrency scams," it added.

In the blog post, Google shared examples of the specific tactics, techniques and procedures (TTPs) used to lure victims, as well as some guidance on how users can further protect themselves.

Cookie Theft, also known as "pass-the-cookie attack," is a session hijacking technique that enables access to user accounts with session cookies stored in the browser.

While the technique has been around for decades, its resurgence as a top security risk could be due to a wider adoption of multi-factor authentication (MFA) making it difficult to conduct abuse, and shifting attacker focus to social engineering tactics, the company said.

Latest News
IPL 2024: Looking to see more attacking fast bowling from Siraj and Yash, says RCB head coach Flower Sat, May 04, 2024, 04:26 PM
Inspiring voices of India's women panchayat leaders resonate at UN meet Sat, May 04, 2024, 04:24 PM
CM, Dy CM obsessed with 'pen drive', forgotten about guarantees: KarnatakaBJP chief Sat, May 04, 2024, 04:21 PM
President Murmu reaches Shimla for five-day visit Sat, May 04, 2024, 04:13 PM
Cracks in the armour: Cong faces serious challenge from NC rebel candidate in Ladakh constituency Sat, May 04, 2024, 04:06 PM
Chinese embassy in Canada refutes foreign interference accusations Sat, May 04, 2024, 03:47 PM
Karnataka CM chairs SIT meeting, orders immediate arrest of Prajwal Revanna Sat, May 04, 2024, 03:42 PM
Study calls for making cardiorespiratory fitness a part of annual check-up Sat, May 04, 2024, 03:35 PM
'Refusing an ICC event can backfire', cautions Rashid Latif amid uncertainty over India's participation in Champions Trophy Sat, May 04, 2024, 03:24 PM
Meta gets 27K reports via Indian grievance mechanism in March, fake FB, Insta profiles key concern Sat, May 04, 2024, 03:23 PM
Government lifts ban on onion exports with price rider Sat, May 04, 2024, 03:22 PM
Multiple fires erupt in Ukraine's Kharkiv after overnight Russian attacks Sat, May 04, 2024, 03:19 PM
UNGA president invokes Mahatma Gandhi to call for protecting journalists Sat, May 04, 2024, 03:18 PM
Rahul's Raebareli move will be 'suicidal', says ex-Congman Pramod Krishnam Sat, May 04, 2024, 03:17 PM
'Shahenshah lives in castle': Priyanka Gandhi's retort on Rahul being dubbed 'Shehzada' Sat, May 04, 2024, 02:55 PM