News: 1637823562

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Google advises passwords are good, spear phishing is bad, and free clouds get attacked

(2021/11/25)


Google's Cybersecurity Action Team has released its first "threat horizon" report on the scary things it's found on the internet.

The advertising giant [1]launched the Team in October 2021, when execs said its ambition was to become "the world's premier security advisory team" and dispense advice that will improve cyber resilience for all.

The Team's [2]first report offers six nuggets of intelligence, and The Register believes none will surprise readers.

[3]

One describes a North Korean government-backed attacker group that has moved on from trying to attack security researchers and now poses as recruitment consultants from Samsung. The group targets workers at South Korean anti-malware devs and sends them poisoned PDFs that, if clicked, drop an executable that allows limited remote control of a victim PC.

[4]

[5]

The report says it's a significant attack because sites like LinkedIn let crims target email-borne attacks, while PDF readers remain a fine way to compromise systems.

Thanks for the intelligence from 2010, Google – spear phishing is not new!

[6]

Google did offer a more novel phishing finding, in the news that Russia's Fancy Bear crime gang has tried to reuse code it deployed in an attack on Yahoo! mail to attack Gmail. Fancy Bear's lazy graphic designers couldn't match Google's CSS, so the login pages sent to targets looked a little bit off. Google has warned us all to watch out for that sort of thing.

Another flash of insight from the report advises that analysis of 50 recently hijacked Google Cloud instances revealed 86 per cent were put to work mining cryptocurrency. Crims got in because, in 48 per cent of cases, operators didn't have a password, had a weak password, or didn't bother authenticating APIs.

[7]A bug introduced 6 months ago brought Google's Cloud Load Balancer to its knees

[8]Google denies Gmail users an early start to the weekend after problems accessing service

[9]JEDI mind tricks: Google said Pentagon contract didn't align with company values. Now it's chasing another defence gig

"Google Cloud customers who stand up non-secure Cloud instances will likely be detected and attacked in a relatively short period of time," the Team warns.

Thanks, Google! We're not sure Reg readers could have figured out that authentication and security are good ideas all on their own. A look at the very nasty BlackMatter ransomware is accompanied by the following piercing analysis:

The presence of BlackMatter ransomware on a network is an indication that a network has been compromised through another means.

Which clears things up nicely. We thought ransomware was brought by a stork.

The Team also spotted abuse of the free tier of Google's cloud to generate bogus YouTube traffic – another attack your correspondent fancies readers may have encountered before.

The Register will leave it to you, dear reader, to determine whether or (cough) not (cough) the document meets Google's aim of delivering "the world's best security advice".

[10]

Perhaps future reports, which are promised to offer "Early Warning announcements about emerging threats requiring immediate action" will prove a little more exciting. ®

Get our [11]Tech Resources



[1] https://www.theregister.com/2021/10/12/google_next_roundup/

[2] https://services.google.com/fh/files/misc/gcat_threathorizons_full_nov2021.pdf

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YZ9s3cy8F-jEdjK2@oBmtgAAAAo&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YZ9s3cy8F-jEdjK2@oBmtgAAAAo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YZ9s3cy8F-jEdjK2@oBmtgAAAAo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YZ9s3cy8F-jEdjK2@oBmtgAAAAo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2021/11/23/google_outage/

[8] https://www.theregister.com/2021/11/12/gmail_down/

[9] https://www.theregister.com/2021/11/04/google_joint_warfighting_cloud_capability/

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YZ9s3cy8F-jEdjK2@oBmtgAAAAo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[11] https://whitepapers.theregister.com/



Is this a joke?

Kevin McMurtrie

Does Google even have a working means of reporting Gmail phishing, GCP hosted hacking and fake stores, trojan horse Play Store apps, Google Calendar hacks, Google Photos hacks, Google Groups scammers, ...

No.

If it hurts competitors more than Google, Google says everyone else needs to do better.

Maybe this isn't so bad.

Anonymous Coward

These things may seem obvious to us, but it seems like some people still don't have a clue. When the "obvious" is the biggest attack vector, it seems logical to address it first.

Chris G

Judging by the advice they give, I am assuming that G CAT is aimed more at the unwashed masses than the likes of Reg readers which is why it has tabloid quality information.

Best line in the article

Giles C

Good job I wasn’t having a drink when I read this

Which clears things up nicely. We thought ransomware was brought by a stork

Detective Emil

Because of [1]stuff like this [New York Times], I'm very wary of security advice from spying organizations — among which I number Google.

[1] https://www.nytimes.com/2013/09/06/us/nsa-foils-much-internet-encryption.html?pagewanted=all&_r=0

Only from...

YetAnotherJoeBlow

I thought that Google was to be reporting actionable intelligence not common attack vectors.

But has any little atom,
While a-sittin' and a-splittin',
Ever stopped to think or CARE
That E = m c**2 ?