×
Tech

New Cybersecurity Warning - How to Protect Gmail and Google Calendar from Credential Hacking Attack

The latest Warning from Cybersecurity researchers necessitates users of Google Services to know more about the threat and learn how to Protect Gmail and Google Calendar from Credential Hacking Attack.

New Cybersecurity Warning - How to Protect Gmail and Google Calendar from Credential Hacking Attack

The wide popularity of Google’s Gmail email service is proved by its huge base of 1.5 billion-plus users. Meanwhile, the Play Store provides a billion plus count of Google Calendar app download. Cybersecurity researchers have warned that threat actors are exploiting the popularity of both Gmail and Google Calendar in order to target users with a credential-stealing attack. So, in case you are feeling vulnerable, here’s what you need to know and do in order to secure your account.


For more technology insights, follow me @Asamanyakm


How does the Attack Target Users?


Cybersecurity researchers working at Kaspersky Lab have disclosed how threat actors are taking advantage of the tight, and automatic, integration between various Google services in order to target users with malicious exploits. The researchers refer to the attack as a sophisticated scam, in which users of the Gmail service are being targeted mainly via malicious and unsolicited Google Calendar notifications. Google has designed the calendar application to work based on the assumption that anyone can schedule a meeting with you. Gmail, which receives the invitation notification, is equally designed to tightly integrate with the event handling calendar functionality.


When a user receives a calendar invitation, a pop-up notification appears on their smart device. The threat actors structure their invitations to include a malicious link, leveraging the trust that user acquaintance with calendar notifications brings with it.


The researchers have observed attackers throughout the last month using this technique to effectively spam users with phishing links to credential hacking websites. By populating the location and topic fields to announce a fake online poll or questionnaire associated with a financial incentive to participate, the threat actors encourage the victim to follow a malicious link where bank account or credit card details can be assimilated. By making the best use of this kind of a non-traditional attack vector, the criminals benefit from the fact that people are increasingly aware of common methods to encourage clicks of weblinks.


What is the Severity of the Threat?


Security awareness experts believe, this attack paves the way for an entirely new gamut of powerful social engineering strikes and may go far beyond the reach of plain phishing. In order to gain access to a building, for example, an attacker could put in a calendar invite for a face to face appointment stating causes such as building maintenance or fire safety check or even webcam installation or maintenance, etc.that could allow physical access to secure areas.


Since the attack is not limited to online users or targeted only at the hacking of sensitive information, it can take mammoth shape if enough awareness is not created amongst users. The cybercrime researchers believe the message needs to go around and users need to be educated on the precautionary steps.


What is Needed to Mitigate the Risk?


Kaspersky experts recommend users to turn off the automatic adding of calendar invitations by going to the [Event Setting] menu in Google Calendar and disabling the [automatically add invitations] option by enabling the [only show invitations to which I've responded] one instead. Furthermore, it is recommended that [Show declined events] in the View Options section is also left unchecked.


If turning off the automatic adding of events to your calendar sounds impractical, and if many of the users rely on this type of scheduling alone, then Boris Cipot, a senior security engineer at Synopsys, has some general mitigation advice suggesting Questioning every email and in this case invitation user receives. If the invite appears weird, wrong or unusual, then the user must ask the sender of this invite if the concerned sender really sent it.


Also, the "do not click on any links or attachments" recommendation obviously needs to be followed. Whenever in suspicion, it's better to delete Cipot warns, but ultimately the Kaspersky advice should be followed he suggests. Automation is not the best option in cases such as this, so do not let your calendar app put invitations automatically into your calendar, Cipot concludes.


It’s better for users to validate meetings in the calendar manually and treat unexpected entries with a hint of suspicion.


What is Google’s stand?


Way back in 2017, researchers Beau Bullock and Michael Felch, working at Black Hills Information Security, were the first to unravel the Google Calendar invitation technique. The full story of that revelation discloses how Google was informed about the vulnerability and responded by silently adding an option to disable the functionality. The researchers found a way to work around that and after the public disclosure and weaponizing of the vulnerability at the Wild West Hackin' Fest 2017, Google contacted the researchers to state that no "fix" had been made because "making this change would cause major functionality drawbacks for legitimate API events with regards to Calendar." In other words, for the technology leader, it was a case of user experience taking priority over security.


Though Google has been contacted over the latest cybersecurity threat, no updates received yet. Google’s Terms of Service and product policies prohibit the spreading of malicious content on their services, and the company works diligently to prevent and proactively address abuse of any form. Combating spam is a never-ending battle, and while Google has made great progress, sometimes spam gets through. According to the tech stalwart, the company remains deeply committed to protecting all of Google users from spam. Google scans content on Photos for spam and provides users the ability to report spam in Calendar, Forms, Google Drive, and Google Photos, as well as block spammers from contacting them on Hangouts. In addition, Google offers security protections for users by warning them of known malicious URLs via Google Chrome's Safe Browsing filters.

ABOUT THE AUTHOR
Jun 17, 2019