New Security Warning Issued For Google’s 1.5 Billion Gmail And Calendar Users

Story by Davey Winder – Forbes

Google’s Gmail email service is used by upwards of 1.5 billion people. The Google Calendar app, meanwhile, has been downloaded more than a billion times from the Play Store. Security researchers have this week warned that threat actors are exploiting the popularity of both in order to target users with a credential-stealing attack.  Here’s what you need to know.

What does this attack involve?

Security researchers working at Kaspersky have revealed how threat actors are using the tight, and automatic, integration between different Google services in order to target users with malicious exploits.

In what the researchers refer to as a “sophisticated scam,” users of the Gmail service are being targeted primarily through the use of malicious and unsolicited Google Calendar notifications. Anyone can schedule a meeting with you, that’s how the calendar application is designed to work. Gmail, which receives the notification of the invitation, is equally designed to tightly integrate with the calendaring functionality.

When a calendar invitation is sent to a user, a pop-up notification appears on their smartphone. The threat actors craft their invitations to include a malicious link, leveraging the trust that user familiarity with calendar notifications brings with it.

The researchers have noticed attackers throughout the last month using this technique to effectively spam users with phishing links to credential stealing sites. By populating the location and topic fields to announce a fake online poll or questionnaire with a financial incentive to participate, the threat actors encourage the victim to follow the malicious link where bank account or credit card details can be collected. By exploiting such a “non-traditional attack vector,” the criminals can get around the fact that people are increasingly aware of common methods to encourage link-clicking.

Is this just a phishing thing then?

“Beyond phishing, this attack opens up the doors for a whole host of social engineering attacks,” says Javvad Malik, security awareness advocate at KnowBe4. Malik told me that in order to gain access to a building, for example, you could put in a calendar invite for an interview or similar face to face appointment such as building maintenance which, he warns “could allow physical access to secure areas.”

Hugo van den Toorn, manager of Offensive Security at Outpost24, agrees that the danger extends beyond the pure phishing realm. “This phishing attack specifically leveraged the intended functionality of a certain mobile application,” van den Toorn explains, “likely they could have also added attachments with malware targeting these users.”

How can you best mitigate the risk?

Kaspersky advises users to turn off the automatic adding of calendar invitations by going to the “Event Setting” menu in Google Calendar and disabling the “automatically add invitations” option by enabling the “only show invitations to which I’ve responded” one instead. Furthermore, it is advised that “Show declined events” in the View Options section is also left unchecked.

If turning off the automatic adding of events to your calendar is impractical, and it’s likely to be just that for many who rely on this type of scheduling, then Boris Cipot, a senior security engineer at Synopsys, has some general mitigation advice. “Question every email and in this case invitation you receive,” he says, “if it feels weird, wrong or unusual then ask the person who sent this invite if they really sent it.”

Obviously, there’s also the “do not click on any links or attachments” advice to be had. “Whenever in doubt it’s better to delete,” Cipot warns, but ultimately the Kaspersky advice should be followed he says. “Automation is not your friend in cases such as this, so do not let your calendar app put invitations automatically into your calendar,” Cipot concludes.

For full story, click here.

Slow phone or computer? How to avoid getting ‘cryptojacked’

By Josh Elliott/Global News – Your computer or smartphone might be helping criminals crank out thousands of dollars in online currency, and you wouldn’t even know it.

A new hacking tool known as “cryptojacking” is on the rise, and it threatens to secretly use your computer to generate online money for cybercriminals.

In the latest case, the Russian online security firm Kaspersky says a downloadable program has generated more than $40,000 by operating in the background on victims’ phones, laptops and work computers. The program has been dubbed “PowerGhost,” and it has yet to be stopped.

Cybercriminals have also found ways to exploit victims’ computers through their web browsers. In one case from January, someone inserted a line of cryptojacking code into an advertisement on YouTube. Victims saw their computers slow to a crawl when the advertisement appeared, as their processors were hijacked to generate money for the cybercriminal.

Experts say potentially thousands of websites and hundreds of thousands of users have been affected by a form of cryptojacking, although its stealthy nature makes it hard to nail down concrete numbers.

Raj Samani, the chief scientist at antivirus-maker McAfee, says cryptojacking is “one of the fastest-growing areas of cybercrime.”

Here’s how to protect yourself in the new age of cryptojacking.

What are they stealing?

Anyone can “mine” their own cryptocurrency by using a computer to solve complex math problems. However, the process can be time- and energy-intensive, making it hard to turn a profit without a large operation or a cheap source of power.

Cryptojacking is all about generating cryptocurrency, an anonymous, decentralized form of online money that can be used to purchase a wide variety of goods and services from internet retailers.

With cryptojacking, hackers are essentially making their victims’ computers do all the work for them. They secretly force thousands of computers to solve math problems in the background, then have the resulting cryptocurrency sent to their own digital wallet. Each computer generates only a small amount of revenue, but their combined efforts can mean big bucks for the cybercriminal.

“It’s the theft of computer resources and it’s the theft of energy,”

Troy Mursch – Bad Packets Report

“They’re stealing your resources to mine cryptocurrency for themselves, and that money goes directly into their pocket.”

This makes corporate networks particularly attractive for cybercriminals, because every computer on the network could be forced to mine cryptocurrency, he said.

“The individual device may not be making the guy rich, but when you rope all these together, … it starts to add up,” Mursch said.