This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. > Find out more here
by Shaun Nichols
19 Jan 2013
Security experts are warning users to be vigilant following the discovery of a new phishing operation which targets Google Apps.
Researchers at Sophos said that the attack poses as a Google log-in screen and is hosted on what appears to be a compromised page within the Ethiopian Red Cross site.
According to Sophos, the attack arrives in the target's inbox as an unsolicited note about a supposed order. The message asks the user to log into what they claim is a Google Docs hosted document in order to review an invoice.
When the user clicks on the link, however, they are redirected to a phishing site designed to resemble the Google Docs log-in screen. The page then asks the user to enter log-in credentials which are presumably harvested by attacker to perform account hijackings.
What is most peculiar about the attack, however, is its choice of host domain. Researchers believe that the phishing page is the result of a breach on the Ethiopian Red Cross website.
"At first glance, you might imagine you are logging into Google Docs to see the content from the email's sender - but a closer examination of the URL bar reveals that this isn't Google at all that you're visiting, but instead a phishing page hidden away on the Ethiopian Red Cross Society's website," Sophos senior technology consultant Graham Cluley wrote in a blog post.
"Of course, you shouldn't enter your credentials on the page - as they are likely to end up in the hands of cybercriminals."
The sites of government agencies, nonprofits and educational institutions have in the past been popular targets for breaches which can lead to the uploading of phishing pages. Users are advised to avoid clicking links in unsolicited email messages and check the URL address of any page which asks for log-in credentials.
Latest stories from Security
Related videos
Related articles
Related jobs
Poll
Which productivity tools do you use for work?
BlackBerry's latest smartphone is a mid-tier handset that will cost less than the Q10 and Z10
Updating your subscription status
Connect with V3.co.uk
It's no longer one or other with web security; you can now have a virtualisation and SaaS hybrid model
BYOD is important for employee satisfaction, but poses challenges in terms of security, productivity loss and costs
Who? Assured Recruitment – Uniting Ambition™ a Sunday...
Microsoft Developer, with VBA and SQL Server (.NET desirable...
(Roc Search, Field Engineer, 2nd Line Support, Desktop...
Digital Project Manager, Agile, Scrum, LAMP, Javascript...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree