HomeSecurityHow hackers use Google servers to insert malware

How hackers use Google servers to inject malware

malwareIn the past, security researchers have encountered cases where notorious hackers were able to use EXIF ​​data of images to hide malicious code. This technique is still widely used to infect web users with malware.

Taking it a step further, it was found that hackers have found a way to distribute malware via trusted Google, such as those at googleusercontent. Unlike malware stored in text files, malicious payloads in images are much harder to detect. Furthermore, it is even more difficult to report malware located on googleusercontent.com to Google.

For those who don't know, googleusercontent is Google's domain for displaying user-provided content, without affecting the security of Google pages.

According to a report by Sucuri, the following code was found in a script that extracts the PayPal security code:

How hackers use Google servers to inject malware

The script reads EXIF ​​data from an image on googleusercontent, which was likely uploaded by someone on a Google+ or Blogger account. When the UserComment section of the EXIF ​​data was decoded, it turned out to be a script that has the ability to upload web shells and arbitrary files.

This indicates a larger threat, as there is no way to detect the malware until the image metadata is checked and decoded. Even after the malware is identified, no one can know the true source of the image.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS