GMail, GTalk phishing scam underway

Attention GMail and GTalk users:  There’s a major spam run underway with social engineering lures to steal your login cretentials.
This image shows a GMail message that purports to be an account termination warning from Google but, if a user is tricked into clicking on the link, he/she is redirected to a fake GMail page requesting the login credentials.

Attention GMail and GTalk users:  There’s a major spam run underway with social engineering lures to steal your login cretentials.

This image shows a GMail message that purports to be an account termination warning from Google but, if a user is tricked into clicking on the link, he/she is redirected to a fake GMail page requesting the login credentials.

gmail phish On the GTalk side, the scam is perpetuated via an IM with a TinyURL link that redirects to a ViddyHo login page.

That page instructs them to enter their Google account information, which is then used to break into the victim’s account and send the link to other users in the victim’s address book or buddy list.

Andrew Ostrow at Mashable says he received several GTalk messages with the scam on the same day:

I became alerted to it when I received IMs from three people I hadn’t talked to in some time within a matter of minutes – one a marketing exec at a prominent startup – with typical phishing jargon “check this out!” with a link to a tinyurl that when clicked, points you to a site called ViddyHo. Apparently, the site sends out the message to all of your Google Talk contacts.

These types of phishing attacks are not new but it’s interesting that Google is the target of a multi-pronged phishing attack at the same time.   Google Accounts, in some cases, are tied to valuable properties — Google Checkout, Google Adsense, etc. — so a compromised account can lead to financial damage.

If you suspect you may have been tricked in this (or any phishing attack), it’s important that you immediately change your account password and security question.  

As always, whenever you encounter a Web site asking for login credentials, stop a think carefully.

* Image via the Wall Street Journal, which got a confirmation from Google on the attacks.

Suggested articles

It’s Not the Trump Sex Tape, It’s a RAT

Criminals are using the end of the Trump presidency to deliver a new remote-access trojan (RAT) variant disguised as a sex video of the outgoing POTUS, researchers report.

biggest headlines 2020

The 5 Most-Wanted Threatpost Stories of 2020

A look back at what was hot with readers — offering a snapshot of the security stories that were most top-of-mind for security professionals and consumers throughout the year.