Security News > 2022 > January > Attackers Exploit Flaw in Google Docs’ Comments Feature

Attackers Exploit Flaw in Google Docs’ Comments Feature
2022-01-06 14:00

Attackers are using the "Comments" feature of Google Docs to send malicious links in a phishing campaign targeted primarily at Outlook users, researchers have discovered.

Researchers from email collaboration and security firm Avanan, a CheckPoint company, first observed "a new, massive wave of hackers leveraging the comment feature in Google Docs" in December, Avanan Cybersecurity Researcher/Analyst Jeremy Fuchs wrote in a report published Thursday.

Avanan first identified that the Comments feature of Google Docs, Sheets and Slides could be exploited to send spam emails in October, but so far Google has not responded to the issue, Fuchs wrote.

Attackers have hit more than 500 inboxes across 30 tenants from more than 100 different Gmail accounts by exploiting the feature of Google's cloud-based word processing app, according to the report.

The campaign appears to signify a ramp up in attacks to exploit the Comments feature of Google's collaboration apps for malicious intent - attacks that likely will continue if left unchecked, researchers said.

In October, as previously mentioned, researchers identified threat actors exploiting the Comments feature for the first time, followed by December's flurry of attacks, which were reported to Google on Jan. 3 "Using the resulting phishing via email through Google's built-in tools," Fuchs wrote.


News URL

https://threatpost.com/attackers-exploit-flaw-google-docs-comments/177412/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Google 141 994 4922 2872 1623 10411