Criminals are using trusted Google services as cover for a wide phishing campaign that steals corporate credentials and, in some cases, installs remote-access software. The malicious path runs through Google-owned domains before reaching attacker-controlled pages for users and filters. The emails use familiar workplace themes, including document reviews, expiring mailboxes, package deliveries, payment notices, voicemail […]
Read the original article: