Hackers take advantage of Google.com to install super sophisticated malware
The c/side security team warns that malware is using the Google.com URL to bypass antivirus protection and silently steal data even though the page is completely legitimate.
Báo Khoa học và Đời sống•20/06/2025
Security experts at c/side have just discovered an extremely sophisticated cyber attack campaign based on Google's legitimate domain name. Hackers have taken advantage of the accounts.google.com URL to redirect to malicious JavaScript code that is difficult for users to detect.
Notably, the malware only activates when the browser meets specific conditions such as having the word “checkout” or running automatically. When activated, the code will connect to the hacker's server, allowing control of the browser and remote data theft.
Thanks to its simple logic and limited running time, the malware has bypassed most of today's anti-virus software. Malicious scripts are transmitted through the OAuth protocol, a familiar security mechanism, making identification even more difficult. Even firewalls and DNS filters can't stop it, because all traffic comes from legitimate Google addresses.
C/side experts advise users to be highly vigilant, limit third-party scripts, and always double-check even trusted websites. Dear readers, please watch more videos : Many scams from AI technology are on the rise | News 141
Comment (0)