HomeCoinsEthereumENS founder warns of Google parody, the user exercises with a fake...

ENS founder warns of Google parody, the user exercises with a fake summons

-

The founder and senior developer of the Ethereum Name Service warned his X -Follower about an “extremely sophisticated” phishing attack, who pretended to be Google and tempt users to publish login information.

The phishing attack uses Google's infrastructure to send a fake alarm to users by informing them that their Google data is shared as a result of a summons with the law enforcement authorities, Nick Johnson said in a contribution from April 16 to X.

“There is the DKIM -Signature check and Google Mail shows it without warnings -it even puts it in the identical conversation as other, legitimate security warnings,” he said.

The fake summons seem to return from a Google no-repry domain. Source: Nick Johnson

As a part of the attack, users are offered the potential of displaying the case materials or protest by clicking on a support sides -link, which in response to Johnson uses a tool with which a web site could be created on a Google SubDomain.

“From there you’ll likely harvest your login information and use to compromise your account. I didn't go any further to ascertain,” he said.

The name of Google Domain makes the e -mail appear legitimate, but Johnson points out that there are still clear signs that it’s a phishing fraud -as it’s forwarded from a personal e -mail address.

Fraudsters use Google Systems

In a report dated April 11, the software company Easydmarc explained that the phishing fraud was working through weapons from Google website.

Anyone with a Google account can create a web site that appears legitimate and is hosted under a trustworthy Google domain.

You also use the Google Oauth app, during which the important thing trick is you could insert every thing you wish within the App-Name field in Google, and use a website via name-ceap you could use to output “no-reply@Google account as from the address and the reply address could be”.

Source: Nick Johnson

“Finally, they forward the message to their victims. Because DKIM only checks the message and her header and never the envelope, the message hands over the signature validation and shows as legitimate message within the user's inbox – also in the identical thread as legitimal security warnings,” said Johnson.

Google will soon prepare countermeasures

In an interview with CoinTelegraph, a Google spokesman said that they’re aware of the issue and the mechanism with which the attacker inserts the “any length text”, inserting the mechanism that can prevent the attack method from working in the longer term.

“We are aware of this class of the targeted attack by the threat actor, rockfoils, and have introduced protective measures last week. These protective measures will soon be fully used, which implies that this possibility is closed for abuse,” said the speaker.

“In the meantime, we encourage users to take over two-factor authentication and passkeys who offer strong protection against such phishing campaigns.”

The spokesman added that Google won’t ever ask for personal account registration information-in one thing-one in a single person, one-off passwords or push notifications or upper users.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

LATEST POSTS

Stablecoin's payment volume reaches USD 94 billion, powered by B2B transfers

Stable coins win as a reliable instrument for digital payments on soil. New data from Artemis show that between January 2023 and February 2025, 94.2...

Midas starts tokenitized T-Bill on Algorand

In the Algorand-Blockchain, the German tokenization protocol Midas has launched a tokenized US Ministry of Finance that gives European investors with state bonds without the...

Bitcoin certain: The European company K33 collects $ 6.2 million for strategic purchases

Trusty editorial content, checked by leading industry experts and experienced editors. AD -open The Norwegian broker K33 is targeting so as to add Bitcoin to its...

Solana signals 40% accident against Ethereum in the midst of the Kühlmemecoin madness

Key Takeaways: Sol/ETH broke under an increasing wedge pattern and signals a possible decrease of 40%.Solanas Memecoin revenue has collapsed since April and weakened the...

Most Popular

bitcoin
Bitcoin (BTC) $ 105,431.25 2.45%
ethereum
Ethereum (ETH) $ 2,592.85 4.43%
tether
Tether (USDT) $ 1.00 0.02%
xrp
XRP (XRP) $ 2.20 4.08%
bnb
BNB (BNB) $ 670.51 2.76%
solana
Solana (SOL) $ 163.24 5.68%
usd-coin
USDC (USDC) $ 1.00 0.00%
dogecoin
Dogecoin (DOGE) $ 0.207212 7.30%
tron
TRON (TRX) $ 0.272823 0.24%
cardano
Cardano (ADA) $ 0.706836 6.32%