Symantec security researchers have identified a sophisticated phishing campaign targeting Google Docs and Google Drive users .
The campaign is based on sending fake emails titled “Documents” and attempting to trick unsuspecting victims into viewing a file stored in Google Docs.
To access the contents of the file, users must follow a link, which leads to a fake login page, identical to that of Google.
Users are then prompted to enter their Google account credentials. Many users may enter their credentials without a second thought, as it is common for a similar login page to appear before users view a Google DOCS via a link.
According to experts, the attackers have created a folder in Google Drive to host the phishing website, so the victims' browser points to the address "google.com", while the login page runs in DOCS preview mode.
“The fake page is hosted on Google servers and uses SSL encryption, making it even more believable,” says Symantec security researcher Nick Johnston.
“The scammers have simply created a folder within a Google Drive account, marked it as “public,” and uploaded a file to it. They then use Google Drive’s “Preview” feature to obtain a publicly accessible URL and include it in their messages.”
“This page redirects users to a real Google Docs document, making the whole attack very convincing. Google accounts are a valuable target for phishers, since they can be used to access many services, including Gmail and Google Play,” explains Johnston.

