Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Extension of the malicious browser has infected 722 users across Latin America since the beginning of 2025

June 8, 2025

New company Atomic MacOS Campation Exploaits Clickfix to focus on Apple users

June 6, 2025

Microsoft helps CBI disassemble the Indian Centers for Japanese Technical Support

June 6, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Hacker groups PINEAPPLE and FLUXROOT abuse Google Cloud for phishing credentials
Global Security

Hacker groups PINEAPPLE and FLUXROOT abuse Google Cloud for phishing credentials

AdminBy AdminJuly 22, 2024No Comments3 Mins Read
Google Cloud for Credential Phishing
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


July 22, 2024Information hallCloud Security / Phishing Attack

Google Cloud for Phishing Credentials

Financially motivated actor codenamed Latin America (LATAM). FLUX ROOT saw the use of Google Cloud serverless projects to orchestrate credential phishing, highlighting the misuse of the cloud computing model for malicious purposes.

“Serverless architectures are attractive to developers and enterprises because of their flexibility, cost-effectiveness and ease of use,” Google said in its biennial release. Threat Horizons Report (PDF) shared with The Hacker News.

“These same features make serverless computing services for all cloud providers attractive to threat actors who use them to deliver and communicate their malware, host and direct users to phishing pages, launch malware and execute malicious scripts, specially designed to work in a serverless environment.”

Cyber ​​security

The campaign involved using Google Cloud container URLs to host phishing credential pages to collect login information associated with Mercado Pago, an online payment platform popular in the LATAM region.

FLUXROOT, according to Google, is a threat known for spreading the Grandoreiro banking trojan, with recent companies also taking advantage of legitimate cloud services such as Microsoft Azure and Dropbox to spread malware.

Separately, Google’s cloud infrastructure was also weaponized by another adversary called PINEAPPLE to distribute another malware known as Astaroth (aka Guildma) in attacks on Brazilian users.

“PINEAPPLE used compromised Google Cloud instances and self-created Google Cloud projects to create container URLs in legitimate Google Cloud serverless domains such as cloudfunctions(.)net and run.app,” Google said. “The URLs were hosted by landing pages that redirected targets to the malicious infrastructure that released Astaroth.”

Additionally, an attacker reportedly attempted to bypass email gateway protections by using mail forwarding services that do not reject messages with a failed sender policy structure (SPF) entries or inclusion of unexpected data in SMTP return path field to cause the DNS query to time out and cause the email authentication to fail.

The search giant said it took steps to mitigate the actions by removing malicious Google Cloud projects and updating it Safe Browsing Lists.

Weaponization of cloud services and infrastructure by threat actors – ranging from illegal mining of cryptocurrencies and consequence with weak configurations to ransomware – was is fed by the increased adoption of the cloud in various industries.

Additionally, this approach has the added benefit of allowing opponents blend in with normal network activitywhich makes detection much more difficult.

“Threat actors are taking advantage of the flexibility and ease of deployment of serverless platforms to distribute malware and host phishing pages,” the company said. “Threat actors abusing cloud services are changing their tactics in response to the detection and mitigation measures defenders are taking.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Extension of the malicious browser has infected 722 users across Latin America since the beginning of 2025

June 8, 2025

New company Atomic MacOS Campation Exploaits Clickfix to focus on Apple users

June 6, 2025

Microsoft helps CBI disassemble the Indian Centers for Japanese Technical Support

June 6, 2025

Expand users’ capabilities and protect against Genai data loss

June 6, 2025

Why are more security leaders choose AEV

June 6, 2025

New data Wiper Pathwiper Data Wiper violates Ukrainian critical infrastructure in 2025 attack

June 6, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Extension of the malicious browser has infected 722 users across Latin America since the beginning of 2025

June 8, 2025

New company Atomic MacOS Campation Exploaits Clickfix to focus on Apple users

June 6, 2025

Microsoft helps CBI disassemble the Indian Centers for Japanese Technical Support

June 6, 2025

Expand users’ capabilities and protect against Genai data loss

June 6, 2025

Why are more security leaders choose AEV

June 6, 2025

New data Wiper Pathwiper Data Wiper violates Ukrainian critical infrastructure in 2025 attack

June 6, 2025

Popular Chrome Extensions API leaks, user data via HTTP and Hard Codes

June 5, 2025

Researchers in detail in detail decisively developing tactics as it expands its geographical volume

June 5, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Extension of the malicious browser has infected 722 users across Latin America since the beginning of 2025

June 8, 2025

New company Atomic MacOS Campation Exploaits Clickfix to focus on Apple users

June 6, 2025

Microsoft helps CBI disassemble the Indian Centers for Japanese Technical Support

June 6, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.