ECONOMY & WORK
MONEY 101
NEWS
PERSONAL FINANCE
NET WORTH
About Us Contact Us Privacy Policy Terms of Use DMCA Opt-out of personalized ads
© Copyright 2023 Market Realist. Market Realist is a registered trademark. All Rights Reserved. People may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.
MARKETREALIST.COM / NEWS

Beware of the new Phishing Attack Which Uses Google Forms; Here's how the Tactic Works

BazaCall phishing scammers are stepping up their game by incorporating Google Forms into their deceptive campaigns. Evolving their tactics, they exploit false urgency and use dynamic URLs, making it challenging for traditional security measures to detect.
PUBLISHED DEC 31, 2023
The Google logo is projected onto a man on | Getty Images | Photo by Leon Neal
The Google logo is projected onto a man on | Getty Images | Photo by Leon Neal
The image of the Google logo is reflected on the eye of a young man | Getty Images | Photo by Leon Neal
The image of the Google logo is reflected on the eye of a young man | Getty Images | Photo by Leon Neal

Google and the services it offers from mail to documents to online forms as well as drive, have become integral parts of life for people working online. But this digital exposure and credibility that the tech giant offers, can also be exploited to fool unsuspecting victims. In a concerning development, the notorious BazaCall phishing scammers are adopting new tactics to enhance the authenticity of their malicious campaigns. Security experts have detected a shift in their modus operandi, with the threat actors now leveraging Google Forms to add a layer of credibility to their deceptive schemes.

The BazaCall phishing attacks, initially observed in 2020, have become more sophisticated with time. In these attacks, cybercriminals send emails disguised as legitimate subscription notices, prompting recipients to contact a so-called support desk urgently. The ruse is to dispute or cancel a fictitious plan, with potential charges ranging from $50 to $500.

To manipulate victims, the attackers induce a sense of urgency, urging targets to engage in a phone call. During this call, scammers convince victims to grant remote access using desktop software, claiming to assist in canceling the alleged subscription. Popular services like Netflix, Hulu, Disney+, Masterclass, McAfee, Norton, and GeekSquad are often impersonated to lure unsuspecting victims.

In the latest variant of BazaCall attacks, cybersecurity firm Abnormal Security has identified the use of Google Forms as a tool to collect details related to fake subscriptions. The attackers cleverly enable response receipts in the form, sending copies of the responses to the victim's email. This manipulation is designed to make the responses appear as payment confirmations for legitimate services, such as Norton Antivirus.

Sitting in front of computer terminals, young people send and receive e-mail at an internet cafe | Getty Images | Photo by Robert Nickelsberg
Sitting in front of computer terminals, young people send and receive e-mail at an internet cafe | Getty Images | Photo by Robert Nickelsberg

The choice of Google Forms introduces an additional layer of cunning, as responses originate from the trusted domain "forms-receipts-noreply@google.com." This tactic increases the likelihood of bypassing secure email gateways, enhancing the phishing campaign's effectiveness. Moreover, Google Forms' use of dynamically generated URLs makes it challenging for traditional security measures to detect and block threats, as these URLs constantly change.

The adoption of Google Forms by BazaCall scammers showcases their adaptability and willingness to exploit trusted platforms. This evolution in tactics, combined with the use of dynamic URLs, poses a significant challenge to conventional security measures. As threat actors continue to refine their methods, organizations and individuals must stay vigilant against phishing attempts to safeguard their sensitive information.

BazaCall's incorporation of Google Forms into their phishing attacks highlights the ever-changing landscape of cybercrime. The blending of social engineering tactics with trusted platforms highlights the need for continuous cybersecurity awareness and advanced threat detection measures. As the threat landscape evolves, security experts emphasize the importance of staying informed and adopting proactive security measures to mitigate the risk of falling victim to such deceptive schemes.

MORE ON MARKET REALIST
Robert Herjavec and Lori Greiner rubbed it in O'Leary's face by celebrating their deal with Phoozy
17 hours ago
Duc and Lisa Nguyen's stubbornness paid off, as the co-founders of Baubles + Soles got Daymond John as a partner.
19 hours ago
The player got the host to be candid about his fears and his mother's opinion on him.
21 hours ago
Justin Baer, founder of Collars & Co., was looking for mentorship from the Sharks in addition to a $300,000 investment.
22 hours ago
She said that her husband may still have to buy a dog as America may hold him accountable.
1 day ago
When Harrison knew that the 18th-century map was the real deal, he made a genuine offer.
1 day ago
10 years after her sister’s win, Chelsea Hall hit the jackpot on ‘WoF’ with a brand new Mini Cooper and a cash prize.
1 day ago
The co-founders of BuggyBeds wowed the Sharks so much, they were "itching" to invest, and offered a $250k deal.
1 day ago
The guests were left stunned to find out just how much the repairs would cost.
2 days ago
Unfortunately for the seller, she allegedly got robbed of a significant amount of money.
2 days ago
Not only did the co-creators of FlingGolf get a $300,000 deal, they proved Mr Wonderful wrong.
2 days ago
The guest never imagined the old, autographed sneakers that his mom acquired could be worth so much.
3 days ago
The gameshow whiz did it again by bagging the top prize on yet another trivia test.
3 days ago
Riccardi took to Reddit to clear the air around his stunning loss which was facing scrutiny.
3 days ago
Fans gathered on the show's unofficial Reddit forum to discuss the 'dumb and useless' items.
4 days ago
The contestant, Matt Benton expressed he wanted to enjoy the moment before thinking of the future.
4 days ago
The guest who treasured the collection had no idea how significant it was.
4 days ago
Even the contestant admitted that there was no way he could've got the answer.
4 days ago
Jennings told TV Insider that Seacrest is a generational talent and there's nothing he couldn't do.
5 days ago
The co-founders of 'Bro Glo' managed to bag the biggest Shark for their innovative self-tanner.
5 days ago