Web Hack List

Collected research

Google Drive SSO Phishing

New Phishing Campaign Leverages Google Drive

Phishing pages were hosted on Google Drive so the link and its HTTPS certificate look like Google own infrastructure, and the page JavaScript was obfuscated so scanners could not read the HTML or rely on IP blacklists. Harvested Google single sign-on credentials were sent to a separate third-party domain.

Record

Document
New Phishing Campaign Leverages Google Drive
Researcher
Ericka Chickowski
Published by
Dark Reading
Topic
Identity

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Ericka Chickowski, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .