Microsoft is warning businesses about hackers using company website contact forms to distribute the info-stealing banking trojan “IcedID” to employees in emails with Google URLs. “Contact us” forms are an open door on the Internet, and criminals have recently begun using them to target employees who receive contact requests from the public. In this malicious activity, scammers use contact forms to send employees legitimate Google URLs that ask users to log in with their Google username and password.
Microsoft considered this a very serious threat, which led it to report the attacks to Googleto warn them that cybercriminals were using legitimate Google URLs to distribute malware. Google URLs are useful to attackers because they bypass email. The malicious actors also appear to have bypassed CAPTCHA challenges that are used to check whether the user submitting a contact request is human or not.
Read also: Joker malware: Infected over 500,000 Huawei Android devices!

Specifically, the Microsoft 365 Defender Threat Intelligence reported the following: “Attackers are abusing legitimate infrastructure, such as website contact forms, to bypass protections, making this threat difficult to detect. Additionally, attackers are using legitimate URLs – in this case Google URLs – that ask users to sign in with their Google credentials.”
Microsoft is concerned about the technique being used and has so far identified criminals using the URLs in emails to distribute the IcedID malware. But it could just as easily be used to distribute other malware.
IcedID is a banking trojan and infostealer that can be used as an entry point for subsequent attacks, such as manually operated ransomware, on high-value targets. Human-operated ransomware attacks are increasingly common and require the attacker to sit at the keyboard and orchestrate the attack, as opposed to an automated attack.

See also: LinkedIn: Hackers hide malware in fake job offers!
This is an attack that is difficult for companies and government agencies to detect, as the email reaches employees from their own contact form and email marketing systems. Since the emails originate from the recipient's contact form on their website, the email templates match what one would expect from a real customer interaction or inquiry.
The attackers use language that pressures the employee to respond, such as false claims that the targeted website uses copyrighted images. The email contains a link to a page on sites.google.com, where the employee is intended to view these images.

Suggestion: Janeleiro: The new banking trojan that targets organizations and governments
If the employee does their job and investigates this claim by logging into the website, the sites.google.com page automatically downloads a ZIP file with a JavaScript file, which in turn downloads the IcedID malware as a .DAT file. It also downloads Cobalt Strike, which allows the attacker to control a device over the Internet.
Information source: zdnet.com
