Hackers changed the target. Now they are attacking Gmail users and bypassing security

Haker

CERT Polska warns against a new phishing campaign. Hackers have targeted Gmail users and can even intercept verification codes.

For years, the target of the UNC1151 hacking group was primarily accounts in Polish email services. Now cybercriminals have changed their tactics and are increasingly focusing on Gmail users. According to CERT Polska experts, the campaign is being conducted on a large scale, and the methods used by the attackers are becoming more and more advanced.

CERT Polska: hackers can bypass two-step verification

The greatest concern is that criminals have learned how to successfully extort two-factor authentication codes. This applies to both codes sent via SMS and those generated by authentication applications.

This means that simply enabling additional security is not always enough if the user himself provides the code on a crafted website. According to experts, this element makes the latest campaign particularly dangerous.

Be careful, it could be you

Analysts indicate that the targets of attacks are primarily people performing important public functions or having access to valuable information. The targets include politicians, officials, journalists, scientists, social activists and uniformed services officers.

At the same time, CERT Polska emphasizes that not all attacks are precisely targeted. Cybercriminals often try to guess the e-mail addresses of their victims, so dangerous messages may also reach random people with similar names and surnames. After taking over the mailbox, attackers are looking for documents, contact lists and data enabling them to take over other accounts, including social media profiles.

This is what the message that is supposed to take over your Gmail account looks like

The attack begins with a message resembling official Google correspondence. The email contains information about an alleged violation of the rules, suspicious login or threat to the account. The recipient is urged to act quickly under the threat of blocking or deleting the mailbox. After clicking the link, you go to a page that is confusingly similar to the real Google login panel.

Entering the login, password and verification code means that the data goes directly to criminals. Additional pressure is exerted by subsequent messages sent at short intervals, which are intended to convince the victim that the matter is urgent.

Hacker creativity knows no limits

Experts point out that the UNC1151 group is constantly developing its tools. Fake login pages are hidden not only on new domains, but sometimes also on hijacked websites belonging to Polish institutions and companies. Thanks to this, fraud can remain undetected for a long time. CERT Polska calls for special caution, carefully checking website addresses and reporting any suspicious messages and websites.

Similar Posts