Experts have discovered a new Google Drive phishing campaign in which attackers deployed phishing web pages on Google Drive.
Once again, phishers are exploiting Google's reputation and running a phishing campaign that aims to steal user Google credentials and thus gain access to multiple services offered by the company.
This new phishing campaign was discovered by security researcher Aditya K. Sood from Elastica Cloud Threat Labs. Also in this case, the phishers used phishing pages hosted on Google Drive that display a similar to the Google log-in page that is “served” over HTTPs. The use of HTTPS makes the pages look more realistic and less suspicious to victims.
This phishing campaign has many similarities to the campaign discovered by Symantec researchers in March 2014, where malicious emails were sent by scammers with the same subject line “Document,” and the stolen credentials were hosted on a third-party server.
The new campaign appears to be an evolution of the previous one, according to the researchers, because advanced cloaking techniques are used on these phishing pages. The phishers used a JavaScript encryption mechanism to disguise the code on the phishing pages.
The attack plan is quite simple, victims receive the fraudulent email from Gmail addresses that are likely to have been compromised, and you ask them to click on the embedded link that appears to be hosted in a Google Drive folder. The phishing page resembles a Google log-in form, then if the user enters their credentials they are automatically transferred to an compromised web server, while the user is redirected to a PDF document hosted on another server to avoid raising suspicion.
The destination URL where the victims' certificates are sent is
ishxxp://alarabia[.]my/images/Fresh/performact[.]php.
Phishers interested in stealing their victims' Google credentials, as explained in the researchers' post.
The researchers also observed that phishing emails are able to evade Google's built-in detection mechanism, most likely because they are sent from a Gmail account and because the embedded link points to a legitimate googledrive.com domain.

