I am seeing a lot – a *lot* – more spam than before.
-
I am seeing a lot – a *lot* – more spam than before. I am not the only one. Seems like some larger phishing campaign got kicked off?
I wonder if this is related to the aggression on Iran.
-
I am seeing a lot – a *lot* – more spam than before. I am not the only one. Seems like some larger phishing campaign got kicked off?
I wonder if this is related to the aggression on Iran.
@rysiek I concur. And the majority is coming via Google mail servers. It seems Google has a problem. Started around a month ago.
-
@rysiek I concur. And the majority is coming via Google mail servers. It seems Google has a problem. Started around a month ago.
@jwildeboer yeah, that's also super confusing.
My best guess would be: this is coming from accounts that got phished a while ago and were just sitting dormant (as in, not used by the malicious actors) for when they were needed.
That time has apparently come now.
-
@jwildeboer yeah, that's also super confusing.
My best guess would be: this is coming from accounts that got phished a while ago and were just sitting dormant (as in, not used by the malicious actors) for when they were needed.
That time has apparently come now.
@rysiek I have sent around 150 reports to Google (for the mails) and Cloudflare (where the phishing sites that are linked in the mails point to) but I see no change for the better. Quite the opposite, actually. It is getting more.
-
undefined oblomov@sociale.network shared this topic
-
I am seeing a lot – a *lot* – more spam than before. I am not the only one. Seems like some larger phishing campaign got kicked off?
I wonder if this is related to the aggression on Iran.
@rysiek on the upside, would they bother with the Fediverse if it didn't actually have some traction?
-
@rysiek on the upside, would they bother with the Fediverse if it didn't actually have some traction?
@oblomov sorry, I should have been clear it's about e-mail spam
-
@rysiek I concur. And the majority is coming via Google mail servers. It seems Google has a problem. Started around a month ago.
@jwildeboer @rysiek I don't do email security stuff anymore but when I did a few years back Google was one of our top sources of spam. I think this may just be an ongoing trend.
-
@jwildeboer @rysiek I don't do email security stuff anymore but when I did a few years back Google was one of our top sources of spam. I think this may just be an ongoing trend.
@nihili I do email security stuff since 25 years (and counting) and this is a new approach that seems to circumvent some of Googles protection mechanisms. It's not really spam, the attackers create support tickets at various companies and somehow they manage to get the auto-replies sent in a way that they are routed through Google but end up in my inbox. It seems these domains act as relays. @rysiek
-
@nihili I do email security stuff since 25 years (and counting) and this is a new approach that seems to circumvent some of Googles protection mechanisms. It's not really spam, the attackers create support tickets at various companies and somehow they manage to get the auto-replies sent in a way that they are routed through Google but end up in my inbox. It seems these domains act as relays. @rysiek
@nihili Another category are real spam and phishing mails that abuse google mail groups. The pattern there is a rather convincing looking mail with "your account has been blocked", "your cloud storage is above limits" with a link to a phishing site behind cloudflare. That started around two months ago. @rysiek
-
@nihili Another category are real spam and phishing mails that abuse google mail groups. The pattern there is a rather convincing looking mail with "your account has been blocked", "your cloud storage is above limits" with a link to a phishing site behind cloudflare. That started around two months ago. @rysiek
@jwildeboer In the samples I have seen on my system, the support ticket mails were just a side effect of the Google Groups spam - a number (but not all) of these groups also seem to relay replies from "subscribers".
To this day I don't understand why the hell allows customers to add foreign email addresses to Groups for Business without a double opt-in - at least that's how I read https://support.google.com/a/answer/9400087#upload
(I also don't understand why Google doesn't seem to detect compromised organizations, but I guess, as in so many things, they just don't care...)