Parker Higgins is a user on mastodon.xyz. You can follow them or interact with them if you have an account anywhere in the fediverse. If you don't, you can sign up here.
Parker Higgins @xor

🚨🚨🚨 Really major Gmail phishing attack going around right now. Do NOT click on an unexpected "Open in Docs" link.

Whether or not you have, now is a great time to review the apps you've authed to your account: security.google.com/settings/s

· Web · 76 · 23

@xor what does it look like after clicking on it? Is it a zero interaction thing or is there the normal "authorize blah blah blah"? What does that page look like?

@nightpool it asks for your e-mail address and password using the old-style google login page where you input both

@nightpool @xor Judging from articles, it sounds like it asks you to authorize an app but it the app has the same name and icon as the actual Google Docs

@chris @xor yeah that's what I thought people had been describing. (cc @kaniini)

interesting if true! I'd probably not have fallen for it, because I use docs on a daily basis and it's never asked for that before, but I can see it being SUPER effective.

@nightpool @xor @kaniini Agreed. I think this is one phishing attack that I might just have fallen for. It is kind of strange that you can make an app with that name though.

@chris @nightpool @xor

what i have been seeing is "open in gdocs" links that send you to a phishing login page and then a fake authorize google apps screen.

i suggest resetting password and verifying you haven't authorized any rogue apps...

@chris @nightpool this is correct. The URL for the app (not displayed but you can hover to see) is a not-Google link. Extremely subtle.

If "Google Docs" appears in the list I linked, nuke it

@xor @chris @nightpool from what I can tell (and based on the conversation on HN) it appears it redirects to googledocs.gdocs.pro after getting the OAuth token. Wish I had an actual example.

@chris @xor @nightpool tl;dr no one should be expecting their apps to have access to their apps on the same service.

@xor Have a link to an article explaining the phishing atttack?

I'm not using gmail, but I'm curious what it's doing.

@cwebber I haven't seen an article, but it's "just" getting oAuth access to mail and contacts for a rogue app named "Google Docs" (then spamming it out)

@xor Yup. I got it, too. Two of them. Weirdly, from the names of the school district clerks.

@xor yeah I didn't get the phishing email, but there were a few things on that list that I took off, so it was a good heads up in any event!
@xor I clicked that link and then went "wait, was that link legit". But it seems you were not phishing me!

@xor Google says it has stopped a phishing email that reached about a million of its users. bbc.com/news/business-39798022