Tuesday, March 31, 2026
Catatonic Times
No Result
View All Result
  • Home
  • Crypto Updates
  • Bitcoin
  • Ethereum
  • Altcoin
  • Blockchain
  • NFT
  • Regulations
  • Analysis
  • Web3
  • More
    • Metaverse
    • Crypto Exchanges
    • DeFi
    • Scam Alert
  • Home
  • Crypto Updates
  • Bitcoin
  • Ethereum
  • Altcoin
  • Blockchain
  • NFT
  • Regulations
  • Analysis
  • Web3
  • More
    • Metaverse
    • Crypto Exchanges
    • DeFi
    • Scam Alert
No Result
View All Result
Catatonic Times
No Result
View All Result

Phishing scammers now exploiting Google’s infrastructure to target crypto users

by Catatonic Times
April 16, 2025
in Scam Alert
Reading Time: 2 mins read
0 0
A A
0
Home Scam Alert
Share on FacebookShare on Twitter



Phishing scams concentrating on crypto customers have grow to be extra superior, with attackers abusing Google’s infrastructure to conduct extremely convincing assaults.

On April 16, Nick Johnson, the founder and lead developer of Ethereum Identify Service (ENS), raised considerations over a contemporary methodology cybercriminals use to compromise Gmail accounts and probably goal related crypto wallets.

How phishing attackers are utilizing Google to their benefit

In line with Johnson, the attackers exploit a loophole in Google’s ecosystem that permits them to ship phishing emails that seem real safety alerts from the tech large itself.

These emails are signed with legitimate DomainKeys Recognized Mail (DKIM) signatures, enabling them to bypass spam filters and seem genuine to recipients.

As soon as opened, these emails direct customers to a counterfeit help portal hosted on a Google subdomain. This faux web page prompts victims to log in and add delicate paperwork.

Nonetheless, Johnson warned that the attackers are doubtless harvesting credentials, which may compromise Gmail accounts and any providers linked to these emails.

The phishing websites are constructed utilizing Google’s Websites platform, which permits customized scripts and embedded content material.

Whereas this flexibility advantages professional customers, it additionally permits malicious actors to create convincing phishing portals. Much more regarding is that there’s presently no strategy to report abuse instantly via the Google Websites interface, making it simpler for attackers to maintain their content material on-line.

He stated:

“Google way back realised that internet hosting public, user-specified content material on google.com is a foul thought, however Google Websites has caught round. IMO they should disable scrips and arbitrary embeds in Websites; that is too highly effective a phishing vector.”

To additional improve the phantasm of legitimacy, the scammers create a Google OAuth utility that codecs and shares the phishing message. These messages are at all times full with structured textual content and what seems to be contact info for Google Authorized Assist.

Google’s response

Johnson reported that he submitted a bug report back to Google about this vulnerability.

Nonetheless, the search engine large reportedly acknowledged that the options work as meant and don’t represent a safety situation.

Johnson wrote:

“I’ve submitted a bug report back to Google about this; sadly they closed it as ‘Working as Meant’ and defined that they don’t take into account it a safety bug.”

However, he urged Google to contemplate limiting script and embedding performance to assist forestall future abuse.

This incident highlights the rising sophistication of phishing campaigns throughout the crypto area. In line with Rip-off Sniffer, almost 6,000 customers misplaced round $6.37 million to phishing scams in March 2025 alone. Within the first quarter of the yr, 22,654 victims suffered whole losses of $21.94 million.

Talked about on this article



Source link

Tags: cryptoexploitingGooglesInfrastructurePhishingScammersTargetUsers
Previous Post

What Happened to Fort Knox Gold Reserve? Inside the Biggest Economic Conspiracy Ever

Next Post

Futureverse Acquires Candy Digital, Taps DC Comics and Netflix IP to Boost Metaverse Strategy

Related Posts

DOJ seizures of 0M expose how crypto investment scams scaled into shift work with quotas and scripts
Scam Alert

DOJ seizures of $580M expose how crypto investment scams scaled into shift work with quotas and scripts

March 4, 2026
MakinaFi hit by .1M Ethereum hack as MEV tactics suspected
Scam Alert

MakinaFi hit by $4.1M Ethereum hack as MEV tactics suspected

January 21, 2026
DeadLock ransomware abuses Polygon blockchain to rotate proxy servers quietly
Scam Alert

DeadLock ransomware abuses Polygon blockchain to rotate proxy servers quietly

January 17, 2026
Tether freezes 2M in USDT, highlighting centralized control in stablecoins
Scam Alert

Tether freezes $182M in USDT, highlighting centralized control in stablecoins

January 13, 2026
How global sanctions are reshaping illicit crypto activity
Scam Alert

How global sanctions are reshaping illicit crypto activity

January 11, 2026
Truebit protocol hack exposes DeFi security risks as TRU token collapses
Scam Alert

Truebit protocol hack exposes DeFi security risks as TRU token collapses

January 9, 2026
Next Post
Futureverse Acquires Candy Digital, Taps DC Comics and Netflix IP to Boost Metaverse Strategy

Futureverse Acquires Candy Digital, Taps DC Comics and Netflix IP to Boost Metaverse Strategy

OKX Relaunches in US with Staged Rollout

OKX Relaunches in US with Staged Rollout

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Catatonic Times

Stay ahead in the cryptocurrency world with Catatonic Times. Get real-time updates, expert analyses, and in-depth blockchain news tailored for investors, enthusiasts, and innovators.

Categories

  • Altcoin
  • Analysis
  • Bitcoin
  • Blockchain
  • Crypto Exchanges
  • Crypto Updates
  • DeFi
  • Ethereum
  • Metaverse
  • NFT
  • Regulations
  • Scam Alert
  • Uncategorized
  • Web3

Latest Updates

  • Chainalysis Deploys AI Agents to Counter Criminal Use of Artificial Intelligence in Crypto – Crypto News Bitcoin News
  • U.S. Bank’s Meghan Kober on Applied Foresight and the Rise of the Participation Economy
  • Bitcoin, Crypto Stocks Climb on Reports That Iran’s President Is ‘Ready to End War’
  • About Us
  • Advertise with Us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact Us

Copyright © 2024 Catatonic Times.
Catatonic Times is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Crypto Updates
  • Bitcoin
  • Ethereum
  • Altcoin
  • Blockchain
  • NFT
  • Regulations
  • Analysis
  • Web3
  • More
    • Metaverse
    • Crypto Exchanges
    • DeFi
    • Scam Alert

Copyright © 2024 Catatonic Times.
Catatonic Times is not responsible for the content of external sites.