It seems that hackers have started using a new phishing campaign, which seeks to steal login information of Facebook and Google users. According to Larry Cashdollar, a security researcher with the Akamai Security Intelligence Response Team, he recently received an email that was flagged by Google as suspicious. The email informed him about a new device that was used to log in to his Google account. Since he had not logged into his account at the time of the warning email, he decided to examine the message more thoroughly.
The email sent from facebook_secur@hotmail.com was a brief report from Google. The first thing that caught his eye was the Hotmail account and that the address had more in common with Facebook than Google. Misusing the name of the famous company is a trick that has been actively used in phishing attacks. In this case, the scammers were trying to trick users into thinking that the notification was from Facebook's security team.
First part of the attack – report from Google
The fake email also included a “Consult the activity” link, which, when clicked, redirects the victim directly to a page that encourages the user to enter their Google account login and password. What is suspicious about this landing page is the Google Translate domain. This is a well-designed choice because when the user sees the URL in the browser bar, the legitimate Google domain appears and creates a false sense of legitimacy.
According to Larry Cashdollar himself, the link address appears legitimate when opened on a mobile device. However, analysis of the email and landing page address on a computer reveals the full domain “translate.googleusercontent.com/translate.”.
If the user notices this address in the first stage of the attack, infection can be prevented. However, when you enter your email and password to log in to your Google account, the attacker can collect the entered information and proceed to the next step of the attack.
Second part of the attack – getting your Facebook credentials
The phishers behind this attack are trying to attack users twice with two different tactics used to obtain Google and Facebook credentials. Once the criminals have your Google account login details, they redirect you to a replica of the Facebook login portal. The phishing attack is clearly aimed at mobile users, and the landing page for Facebook displays a mobile version of the login.
According to Cashdollar, the first credentials collected are your Google account email and password. Later, other information may be collected, such as:
- IP addresses
- browser type
- location
- additional personal information
Users should note that the collected data can later be used to steal more valuable credentials from victims in other attacks.
