Hackers used Google Drive to attack Tibetans

Namtso lake in Tibet

Tibetans and pro-democracy activists in China are often the victims of cyberattacks, but a public campaign to educate people against blindly opening email attachments has been a big success. Unfortunately, as Motherboard reports, this has had the knock-on effect of forcing hackers into being a lot smarter with their subterfuge. Since would-be victims are now wary of opening attachments, nefarious types are now using Google Drive as a trojan horse with which to breach targeted systems.

The research was carried out by CitizenLab, the University of Toronto’s research group that studies the intersection of human rights and digital communications. As it lays out in this blog post, the scam works like this: a hacker sets up an email address that’s similar to a legitimate advocacy group, like the International Tibet Network. They even go so far as to include the mundanities of the ITN’s postal address in the signature to ensure it looks legitimate.

Then, they’ll send the victim a message containing a PowerPoint deck that, on the surface, pretends to be displaying useful information that’s been stored on Google Drive. In fact, the Lab believes that the documents are “repurposing material from legitimate presentations” to better dupe users. Since .PPS files aren’t displayed properly on Google Drive, users would then be tempted to download the file that otherwise appears genuine.

Hidden inside the file is a vulnerability codenamed CVE-2014-4114 which has been found in all versions of Windows since Vista. Unfortunately, the Lab has found that the weakness has a very low detection rate, so your antivirus system isn’t going to catch it should you mistakenly click the link.

CitizenLab can’t speak with any authority as to who could possibly want to disrupt and attack Tibetan and pro-Democracy activists in China, but we can probably all guess. The report does, however, point to an AlienVault study that suggests that the creator of the strain of malware used in the attacks works for a Chinese security firm. The piece concludes that this shift in tactics is concerning since the methods are getting more sophisticated in the face of public education campaigns, but hey – at least it shows that the project is working.

[Image Credit: Getty]

Filed under: Internet

Comments

Via: Motherboard

Source: CitizenLab

Latest posts

Siri won’t be your AI girlfriend

‘Listen, that's not what I'm here for, right?' | Image: Apple Our early testing has already shown that Siri AI knows when to shut up,...

Amazon’s Echo Hub gets a customizable new look and Ring’s AI features

Amazon's rolling out a free software update for Echo Hub devices that gives the home screen a much-needed update to the interface it launched...

Telegram brings back its Wear OS app after five years with chats, voice messages, more

Five years after killing its Wear OS app, Telegram is reviving support for Android smartwatches with its latest update. Read more @ 9to5google

Waze now shows traffic lights on your route, but it’s rolling out slowly

In testing for several months now, Waze is starting to roll out traffic lights more widely in navigation, but it’s still not available to...

Here are the price-matching policies for Best Buy, GameStop, and others

Nothing is more frustrating than buying a new pair of headphones, an OLED TV, or a laptop just to find out that you could...

The bill that would let Jimmy Kimmel sue Brendan Carr is here

Under a new bipartisan bill, Americans could sue for damages if a government official illegally tries to coerce a social media, AI, or broadcasting...

Amazon’s data centers used 2.5 billion gallons of water last year

Just after Seattle enacted a one-year data center moratorium that some of Amazon's own employees pushed for, Amazon shared how much water its data...

Roborock’s Q10 S5 Plus robovac is over half off, matching its best price to date

Roborock’s Q10 S5 Plus comes with a self-emptying dock and is under $300. | Image: Roborock Even at full price, the Roborock Q10 S5 Plus...

Blink’s six-piece outdoor camera kit is a great deal under $200

You can save on a big set of outdoor security cameras ahead of Prime Day. Amazon has a five-pack of Blink cameras with a...

Logitech’s awesome MX Master 3S mouse drops to under $100

The platform-agnostic Logitech MX Master 3S wireless mouse is discounted to $89.99 at Amazon ($30 off), matching the best price we’ve seen so far...