Vietnam.vn - Nền tảng quảng bá Việt Nam

Độc lập - Tự do - Hạnh phúc

Gmail users face unprecedented phishing campaign

With extremely sophisticated methods, taking advantage of Microsoft's legitimate infrastructure to bypass security filters and steal login information.

Báo Khoa học và Đời sốngBáo Khoa học và Đời sống20/08/2025

The scam begins with fake “New Voice Notification” emails that appear to come from legitimate voicemail services.

The email includes a “Listen to Voicemail” button that, when clicked, takes the victim through several intermediary websites, including a fake CAPTCHA page to create a sense of security, before redirecting to a complete replica of the Gmail login page.

Phishing emails use "new voicemail" notifications to lure users into logging in. Photo: SCS

Here, users are tricked into entering their email, password, and additional layers of security such as two-factor authentication, backup codes, and security questions. All data is immediately sent to a server controlled by the attacker.

What makes this campaign particularly dangerous is that the attackers used the Microsoft Dynamics platform (mkt.dynamics.com), a legitimate marketing service, to host the first stage.

This makes it harder for the email to be flagged as suspicious. The malware that creates the fake login page also uses AES encryption to hide it, has anti-debugging features, and redirects it through multiple servers in Russia and Pakistan to make the investigation more difficult.

Experts warn that this is a major step forward in fraud techniques, combining both sociology (creating trust with CAPTCHA, Google interface) and taking advantage of legitimate infrastructure to evade censorship.

Gmail passwords are easily stolen by phishing.

In another development, PCWorld said users of Google services, such as Gmail and Google Cloud, are facing a significant increase in phishing attempts.

A Reddit post points out that Gmail users are now being targeted by text message phishing attacks from phone numbers with the 650 area code.

Scammers claiming to be from Google contact victims to warn them about a security vulnerability affecting their accounts. In these calls, the attackers attempt to take over the victims’ Gmail accounts by asking them to reset their passwords and provide this information.

Additionally, another phishing technique known as “dangling bucket” has been reported, in which hackers test outdated login addresses to install malware on Google Cloud accounts or steal data.

With 2.5 billion Gmail and Google Cloud users, both businesses and individuals need to be vigilant against the rise of phishing attempts and online attacks.

What should users do?

  • - Always be wary of strange voicemail notification emails.
  • - Only log in to Gmail via Google's official website.
  • - If you suspect you've entered information on a fake site, immediately change your password, check recent login activity, and re-enable security layers.
  • - Organizations should implement advanced email filtering solutions and train employees on new forms of phishing.

Security teams are also advised to block domains associated with this campaign, particularly horkyrown[.]com, which has been identified as part of the attack infrastructure.

Google
Original article link Copy link
https://support.google.com/voice/thread/235505162/google-voice-scam?hl=en

Source: https://khoahocdoisong.vn/nguoi-dung-gmail-doi-mat-chien-dich-lua-dao-chua-tung-co-post2149046980.html


Comment (0)

No data
No data
People joyfully welcome the 80th anniversary of National Day
Vietnam women's team beat Thailand to win bronze medal: Hai Yen, Huynh Nhu, Bich Thuy shine
People flock to Hanoi, immersing themselves in the heroic atmosphere before National Day.
Suggested locations to watch the parade on National Day September 2
Visit Nha Xa silk village
See beautiful photos taken by flycam by photographer Hoang Le Giang
When young people tell patriotic stories through fashion
More than 8,800 volunteers in the capital are ready to contribute to the A80 festival.
The moment the SU-30MK2 "cuts the wind", air gathers on the back of the wings like white clouds
'Vietnam - Proudly Stepping Forward to the Future' Spreads National Pride

Heritage

Figure

Enterprise

No videos available

News

Political System

Destination

Product