A new wave of phishing attacks launched against Gmail users has been spotted online, but this time cybercriminals are using a more sophisticated technique that is quite difficult to detect at first glance.

Specifically, attackers are now sending emails to Gmail users with embedded attachments that look like images and which require only a click to launch what is supposed to be a preview of the image.
Instead, the attachment opens a new tab in your browser, requiring you to sign in again. When inspecting the typical elements that could indicate a phishing scam, such as the address bar, everything looks legitimate, as in this case the URL is: “data:text/html,https://accounts/google.com.”
So of course, most users will provide their Gmail credentials, but as WordFence points out, once you do that, your account will be at risk.
Surprisingly, the hacked Gmail account is accessed almost instantly, in order to retrieve the contacts and then use the same phishing email to spread the attack. Using email addresses from a person's contacts can make the emails look even more legitimate, thus helping to compromise a larger number of accounts.
The most likely scenario is that the access is done automatically by a bot, but there is also a possibility for attackers to do the whole thing manually in order to collect email addresses.
The easiest way to keep your account safe, even if you fall victim to a phishing , is to enable two-factor authentication for Gmail, which means that if you provide your credentials to a phishing page, the hacker won't be able to access your account anyway.
