Attackers Using Google Drive Notifications to Trick the Users in Clicking Malicious Links

Scammers found a new phishing lure to play with Google Drive.  An unpatched security loophole within the Drive is being exploited to send seemingly legitimate emails and push notifications from Google that, if opened, could land people on malicious websites.

Users reported that they have received Google Drive notifications in Russian or English asking them to collaborate on unfamiliar documents. Those documents contained links to scam websites. An email notification is received from Google which contains a potentially malicious link.

These links tempt the recipients into reviewing their bank account activity, accepting a cash prize, advertising deals, and/or prize selection. The smartest part of the scam is that the emails and notifications it generates come directly from Google. 

During this scam, the attackers used the Google service’s collaboration feature to create a push notification and/or email inviting people to collaborate on a document containing a link that led to a malicious website.

WIRED explained that phishers likely chose this tactic to urge their attack emails into users’ inboxes and past people’s suspicions:

“The success of email spam filters has left scammers trying to find new ways to urge people to click on malicious links. And Google Drive is pretty accommodating. By default, Drive wants you to understand when someone has mentioned you on a document. In a work setting, this could be a colleague asking you to check over a slide in a presentation or a brief for a new project. For scammers, it’s a clever way of putting a malicious link right in front of a potential victim.”

Some users indicated to WIRED that they had received several forms of the attack as well. Acknowledging this scam technique, a Google spokesperson communicated to WIRED that Google was within the process of performing new security measures that might make it harder for Google Drive spam to avoid its systems.

“Avoid clicking on unsolicited links of any kind when sent from unknown sources. If you weren’t expecting to receive it and don’t know the sender, don’t respond.” says David Emm, Principal Security Researcher at Cybersecurity firm Kaspersky.

This scam wave highlights the necessity for users to get on the watchtower for email-borne attacks. Organizations can help their users in this regard by educating them about a number of the foremost common sorts of phishing attacks that are in circulation today.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Also Read

JhoneRAT – Hackers Launching New Cloud-based Python RAT to Steal Data From Google Drive, Twitter & Google Forms

Hackers Hosting Malware On Google Sites To Steal Data and Share It to the Remote Server

Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

‘RemoteMonologue’ New Red Team Technique Exploits DCOM To Steal NTLM Credentials Remotely

A sophisticated new red team technique dubbed "RemoteMonologue" has emerged, enabling attackers to remotely harvest…

3 minutes ago

OpenSSH 10.0 Released: New Protocol Changes and Key Security Improvements

The OpenSSH team has announced the release of OpenSSH 10.0 on April 9, marking an important milestone…

20 minutes ago

PAN-OS Command Injection Flaw Lets Hackers Execute Arbitrary Code Remotely

Palo Alto Networks has disclosed a medium-severity vulnerability (CVE-2025-0127) in its PAN-OS software, enabling authenticated…

31 minutes ago

Researchers Uncover Hacking Tools and Techniques Shared on Russian-Speaking Cybercrime Forums

Trend Micro, a cybersecurity firm, has released its 50th installment report on the Russian-speaking cybercriminal…

10 hours ago

SideCopy APT Hackers Impersonate Government Officials to Deploy Open-Source XenoRAT Tool

The Pakistan-linked Advanced Persistent Threat (APT) group known as SideCopy has significantly expanded its targeting…

12 hours ago

Russian APT Hackers Use Device Code Phishing Technique to Bypass MFA

Russian state-backed advanced persistent threat (APT) group Storm-2372 has exploited device code phishing to bypass…

12 hours ago