News: 1612949412

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

No phish for the likes of you, thank you very much! Google finds email villains are picky about demographics, country

(2021/02/10)


Kind old Google has [1]published data on targeted email attacks and dispensed advice to help users separate friend from foe.

The pandemic has presented malware-laden email flingers with a world of opportunity and a whole new set of attack vectors. Google noted that it had seen 18 million daily malware and phishing emails related to COVID-19 on top of the over [2]240 million COVID daily spam messages early in the pandemic.

[3]

Google and researchers at Stanford University studied five months' worth of phishing and malware campaigns and concluded the US and the UK were the most popular targets. The same English email template also tended to get used, although localisation was improving; 78 per cent of attacks in Japan were in Japanese, for example.

The campaigns were usually brief, lasting for only a few days with between 100 and 1,000 targets, it found.

[4]

Researchers also modelled what factors put a user at a higher risk. Having your private data exposed in a breach is a given when it comes to sweetening the pot. However, where a user lives plays a part as well. While the US was the most popular target by sheer volume, Australians face double the odds of an attack per capita. The chances of being on the receiving end of a campaign was also 1.64x higher for 55 to 64-year-olds than those in the 18-24 bracket.

The conclusion was the risk is not evenly spread over demographic and geographic boundaries.

It being an emission from Google Cloud, the report recommended making use of Mountain View's phishing and malware protections. For those less inclined to make use of the Chocolate Factory's wares, a bit of common-sense advice from the UK's National Cyber Security Centre wouldn't go amiss: you can find steps to help you identify the most common phishing attacks [5]here .

The Register peered into our own big bucket o' spam to see what delights lurked within and found the beauty you see below.

[6]

Click to enlarge

No, it was not an actual email related to Tesco (although the retailer had sent a genuine one requesting we re-enter our card details, which felt a bit phishy) but we could not help but notice that the links led back to that stout slayer of spam: Google and its API.

[7]

A Google spokesperson told The Register : "When an email is flagged for phishing, our priority is to keep our users safe. We look at many security signals, and malicious links is one of them, before taking appropriate action – one of which may be account suspension." ®

Get our [8]Tech Resources



[1] https://cloud.google.com/blog/products/workspace/how-gmail-helps-users-avoid-email-scams

[2] https://www.theregister.com/2020/04/17/google_coronavirus_spam/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YCO8yoiBYkMXTpj4QN2lnAAAAAI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YCO8yoiBYkMXTpj4QN2lnAAAAAI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.ncsc.gov.uk/collection/small-business-guide/avoiding-phishing-attacks

[6] https://regmedia.co.uk/2021/02/09/tesco.jpg

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YCO8yoiBYkMXTpj4QN2lnAAAAAI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://whitepapers.theregister.com/

I don't find Google blocks too well

MrMerrymaker

Still using a Gmail account like an idiot, I do get spam through to the inbox on occasion.

Like this Tesco email, the entire content is an image with zero text. And Gmail does not let you filter messages that are just an image (nor am I sure I would always want to). With no words in the body, it is difficult to filter at all, as the senders change every time.

More research, more action welcome.

Re: I don't find Google blocks too well

Pascal Monett

So you're saying that you get emails with no subject and no content outside of an image. It seems that that would be a pretty clear indicator of spam in itself, why would you not want that filtered ?

Re: I don't find Google blocks too well

Potemkine!

I've got much less phishing on Gmail than on Outlook/Office365. Obvious phishing comes regularly in my inbox, whatever the reports I submit to MS.

Re: I don't find Google blocks too well

Doctor Syntax

But there's not a lot of point in sending emails from Microsoft telling you they're going to close your account to a gmail address.

Who gets the least?

Uplink

If I "move" to Nigeria will all spam disappear?

Re: Who gets the least?

Andy Non

I've got a relative who's a prince in Nigeria, he'll happily provide accommodation for you. Just send me £1,000 deposit.

Google...

Doctor Syntax

...they should know. After all, most of the spam comes from gmail addresses.

Re: most of the spam comes from gmail addresses.

Anonymous Coward

Or from a spoofed e-mail address with a "contact us at LegitimateBarristerNotAScammerISwear@gmail.com".

Basically, I want people to know that when they use binary-only modules,
it's THEIR problem. I want people to know that in their bones, and I
want it shouted out from the rooftops. I want people to wake up in a
cold sweat every once in a while if they use binary-only modules.

- Linus Torvalds on linux-kernel