HomeSecurityGoogle Drive held data from government computers

Google Drive held data from government computers

google drive

A new malware used by cybercriminals in a targeted attack attempts to gather information about the victim and upload the data to Google Drive.

Dubbed Drigo, it is a type of Trojan that starts searching for a specific set of files in certain locations on the hard drive. It then sends the data for storage to Google Drive.

Attackers are selective in the file formats they search for and limit their search to XLSX, XLS, DOC, DOCX, PDF, TXT, PPT and PPTX files found in places like the Recycle Bin and Documents, as well as other directories.

After analyzing the malware, Trend Micro researcher Kervin Alintanahin discovered that the crooks behind it use the OAuth protocol for authentication. To do this, they encode the CLIENT_ID and client_secret sessions, along with a token refresh, to prevent the OAuth token from expiring.

According to the researcher, the documents sent to Google's cloud revealed the names of the targets, and most of them were government agencies.

From the name of one document, it appears that the victims are in China. Alintanahin said that files from the compromised computers were still visible in the attacker's online storage.

Based on observations during the investigation, it appears that the malware is only capable of uploading documents to Google Drive.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS