Threat Intelligence

12/26/2018
03:00 PM
0%
100%

Attackers Use Google Cloud to Target US, UK Banks

Employees at financial services firms hit with an email attack campaign abusing a Google Cloud storage service.

A malicious email campaign has been found abusing a Google Cloud Storage service to host a payload sent to employees of financial services organizations, Menlo Labs researchers report.

The threat appears to have been active in the US and UK since August 2018. Victims receive emails containing links to archive files; researchers say all instances in this particular campaign have been .zip or .gz files. All cases involve a payload hosted on storage.googleapis.com, which appears to be related to Google's cloud storage service but is, in fact, a malicious link.

Attackers often use this domain to host payloads because it's trusted and likely to bypass security controls in commercial threat detection products. These actors may have chosen bad links in lieu of malicious attachments because many email security products are designed to detect files and only pick up on malicious URLs if they're already in their threat repositories.

The use of a link resembling Google's cloud storage service is a form of "reputation jacking," a tactic in which attackers abuse well-known hosting services to evade detection. It's a growing trend, researchers say: In its annual analysis of the top 100,000 domains as ranked by Alexa, Menlo Labs found 4,600 phishing sites that used legitimate hosting services.

Google has responded to the report. "We regularly remove malware on Google Cloud Storage, and our automated systems suspended the malware referred to in this report," a spokesperson says. Further, account holders who suspect abuse can report it via Google's site.

Read more details here.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
DavidHamilton
50%
50%
DavidHamilton,
User Rank: Apprentice
1/10/2019 | 11:33:58 PM
Cloud storage perks and cons
Cloud storage has its pros and cons and when it is being utilized on a large scale by organisations, they ought to review the security aspects of it. The amount of data that is being uploaded online is massive and they should be noted that, that particular set of data is actually going to remain in the digital realm for good. If they are willing to grasp this concept, then only should they utilize the cloud facility, else they should really just stick to traditional data storage means.
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
1/3/2019 | 10:05:32 AM
Re: Security practice
Gee, what a surprise?  Hackers using the cloud, imagine that.  Give them ANY open door and they are happy to enter any way they can.  The cloud, long vaunted, is one such door.  Anybody remember the words of dear WOZniak ages ago - there is NO security in the cloud.  A lamented savant of the truth. 
markgrogan
50%
50%
markgrogan,
User Rank: Apprentice
1/2/2019 | 11:30:06 PM
Security practice
Are you really surfside that people would try to do this with a cloud-based storage system? Of course there are hackers everywhere who are going to try and get all of this information out of the cloud to use for their own advantage! We just need to take that information and translate it into better security practices!
Crowdsourced vs. Traditional Pen Testing
Alex Haynes, Chief Information Security Officer, CDL,  3/19/2019
BEC Scammer Pleads Guilty
Dark Reading Staff 3/20/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
The State of Cyber Security Incident Response
The State of Cyber Security Incident Response
Organizations are responding to new threats with new processes for detecting and mitigating them. Here's a look at how the discipline of incident response is evolving.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-10014
PUBLISHED: 2019-03-24
In DedeCMS 5.7SP2, member/resetpassword.php allows remote authenticated users to reset the passwords of arbitrary users via a modified id parameter, because the key parameter is not properly validated.
CVE-2019-10015
PUBLISHED: 2019-03-24
baigoStudio baigoSSO v3.0.1 allows remote attackers to execute arbitrary PHP code via the first form field of a configuration screen, because this code is written to the BG_SITE_NAME field in the opt_base.inc.php file.
CVE-2019-10017
PUBLISHED: 2019-03-24
CMS Made Simple 2.2.10 has XSS via the advanced_search.php Name field, which is reachable via an "Add a new Profile" action to the File Picker.
CVE-2019-10010
PUBLISHED: 2019-03-24
Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library before 0.18.3 allows remote attackers to insert unsafe links into HTML by using double-encoded HTML entities that are not properly escaped during rendering, a different vulnerability than CVE-2018-20583.
CVE-2019-9978
PUBLISHED: 2019-03-24
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social Warfare Pro.