Topics Tools Books & Guides Talk to Securafy

Knowledge Hub / IT Operations

IT Operations

Hackers Are Using Legitimate Google Services To Wreak Havoc

Hackers Are Using Legitimate Google Services To Wreak Havoc

Randy Hall By Randy Hall Updated Jul 2024 2 min read Share

The Microsoft 365 Defender Threat Intelligence Team recently issued a dire warning that every IT professional should take seriously.

They've discovered an emerging threat in the form of hackers utilizing legitimate "Contact Us" forms associated with Google websites to distribute malware to unsuspecting site visitors.

Since the website is legitimate, it almost always bypasses email security filters and also sometimes even bypasses CAPTCHA challenges.

Right now, the hackers are using this novel attack vector primarily to infect users with the IcedID info-stealing banking Trojan, but as the team notes, there's no particular reason that they couldn't shift gears at any moment and start infecting people with something even more directly damaging to target systems.

The Redmond giant thought that the threat was dire enough that they reached out to Google directly to warn them. Although the company is now aware, there has yet been any word about what Google will do to keep it from happening, or when that might happen.

For now, just be aware that if any of your employees get an email that appears to be from Google, and sends a user to a legitimate Google "Contact Us" form, it may well be a ploy designed to infect the recipient's system. Then hackers can start stealing all manners of information, starting with the recipient's Google login credentials.

It's proof positive that no company, no matter how large, and no matter how elaborate its security measures, is immune. As mentioned above, by leveraging the legitimate URLs of a trusted company that serves as one of the cornerstones of the web itself, there's really no limit to the amount of damage the hackers could potentially do.

As ever, vigilance is the best defense. Stay on your guard and impress upon your employees that they are not safe.

Join The Conversation

Have a question or perspective on this topic? Add it below.

Randy Hall

About The Author

Randy Hall · CEO & Founder

Randy Hall is the CEO and Founder of Securafy, with decades of experience helping organizations make smarter, safer decisions about technology.

A frequent speaker and instructor at national IT events, Randy has advised thousands of organizations, from startups and SMBs to large enterprises and U.S. government entities, on secure, practical technology adoption. He writes about the decisions business leaders are often expected to make without enough context, including cybersecurity, compliance, AI, cyber insurance, IT strategy, and business resilience.

Outside the office, you’ll often find Randy on Lake Erie enjoying time on his 38-foot Chris-Craft.

Writes about: Cybersecurity strategy, compliance, AI security, business resilience, cyber insurance, SMB risk, IT leadership

More From This Author →

Get Practical Cybersecurity Field Notes

Monthly cybersecurity, compliance, and IT strategy updates from Securafy, written for business owners who need clear next steps.

  • Practical security tips from our Cyber Security Drip series
  • The Securafy Times, our monthly roundup on compliance and IT strategy
  • Occasional updates on new tools, guides, and research
  • No spam — unsubscribe anytime