February 25, 2020 By Shane Schick 2 min read

Phishing campaigns aimed at stealing Microsoft user credentials are using Google Forms to dupe potential victims, security researchers warn.

Cybercriminals managed to increase their odds of success by breaking into a legitimate website to host and send bogus email messages, according to a report from Cofense.

The phishing messages masquerade as important alerts from the company’s IT department asking recipients to update their Office 365 suite of applications or face having their account suspended. Clicking on an “Update Now” button in Google Forms after entering their username and password sends the victim’s credentials to the attackers.

Take a Closer Look

The external Google webpage provides an authentic SSL certificate, researchers explained, which makes it even more likely that users will be fooled into complying with the phishing email’s request.

If they take the time to look more carefully, however, Office 365 users might notice some aberrations in the phony Microsoft login page. Some of the tell-tale signs include the use of asterisks rather than letters and capitalizing more than half of the letters on the page. Unlike a legitimate login page where passwords would be obscured, the credentials appear in plain text as a victim types them in. This happens even before they click the “Update Now” button on the form.

Researchers suggested the technique has been used in multiple phishing campaigns, most of which have been discovered over the past several weeks. Google is not alone in having its technology harnessed for nefarious purposes. Just last month researchers uncovered a phishing technique that made use of Microsoft’s Sway application.

Don’t Fall for Fraudulent Google Forms

Unfortunately, most organizations don’t think through how they would react to a successful phishing attempt, which is why simulation exercises can be helpful. Sometimes attackers will still be successful, so ensure remediation measures for phishing attacks are woven into an incident response plan that involves all departments from human resources to IT.

More from

The compelling need for cloud-native data protection

4 min read - Cloud environments were frequent targets for cyber attackers in 2023. Eighty-two percent of breaches that involved data stored in the cloud were in public, private or multi-cloud environments. Attackers gained the most access to multi-cloud environments, with 39% of breaches spanning multi-cloud environments because of the more complicated security issues. The cost of these cloud breaches totaled $4.75 million, higher than the average cost of $4.45 million for all data breaches.The reason for this high cost is not only the…

What is the Open-Source Software Security Initiative (OS3I)?

3 min read - The Open-Source Software Security Initiative (OS3I) recently released Securing the Open-Source Software Ecosystem report, which details the members’ current priorities and recommended cybersecurity solutions. The accompanying fact sheet also provides the highlights of the report. The OS3I includes both federal departments and agencies working together to deliver policy solutions to secure and defend the ecosystem. The new initiative is part of the overall National Cybersecurity Strategy. After the Log4Shell vulnerability in 2021, the Biden-Harris administration committed to improving the security…

Widespread exploitation of recently disclosed Ivanti vulnerabilities

6 min read - IBM X-Force has assisted several organizations in responding to successful compromises involving the Ivanti appliance vulnerabilities disclosed in January 2024. Analysis of these incidents has identified several Ivanti file modifications that align with current public reporting. Additionally, IBM researchers have observed specific attack techniques involving the theft of authentication token data not readily noted in current public sources. The blog details the results of this research to assist organizations in protecting against these threats. Key Findings: IBM research teams have…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today