Malware targeting Gmail users discovered: 'Be careful' warning

It has been revealed that a software vulnerability in Google's Gmail application is being used to hijack user accounts. Internet hackers using a piece of software called Asteroth are bypassing Google's two-factor authentication, allowing them to steal Gmail accounts. Experts have warned Gmail users to be cautious against Asteroth.

12punto

Cybersecurity experts have urged Gmail users to be cautious against a new phishing attack that bypasses two-factor authentication (2FA). It has been discovered that a malicious software called Astaroth steals users' login credentials, authentication codes, and session cookies in real time. Researchers pointed out that the cyberattack method developed via Astaroth threatens more than 2 billion users who utilize popular email services such as Gmail, Yahoo, AOL, and Microsoft Outlook. It was stated that Gmail is the platform where Astaroth is most effective among email applications.

Researchers noted that Astaroth redirects users to a fake login page. It was reported that this page mimics the interface of the real email service and copies users' credentials when they enter them.

According to a report by the Daily Mail, experts said that users do not realize the attack because they do not see any security warnings on the fake page. It was stated that attackers can use the information they obtain to take over accounts or sell them on the dark web.

Cybersecurity firm SlashNext reported that Astaroth is sold to hackers on the dark web for just 2 thousand dollars. SlashNext alleged that the unidentified seller provides six-month updates, allowing attackers to bypass cybersecurity measures. It was explained that this situation makes it difficult to detect and block the attack.

HOW DOES CYBER FRAUD OCCUR?

Phishing attacks usually begin with users clicking on a suspicious link. These links are often sent via fake emails containing attractive offers, such as claims that bank details have been compromised or promises of refunds. When users click these links, they lose their personal information to fraudsters.

Google announced that it blocks approximately 100 million phishing emails every day. Authorities emphasized that users must also be careful to prevent such attacks. In its statement, Google warned its users not to click on suspicious links and to keep security measures like 2FA active.

According to cybersecurity experts, the way Astaroth works relies on redirecting user browser requests to a malicious server. The software allows this server to act as an intermediary between the real email service and the victim.

During this process, all information entered by the user is transmitted to the attacker. The attacker can use this information to access accounts and offer the stolen data for sale on the dark web.

Experts reminded that the most effective way to protect against phishing attacks is to be cautious against suspicious emails and links. Google pointed out that users should be wary, especially of emails requesting personal information, and should verify messages that claim to be from official institutions. Experts emphasized that using additional security measures like 2FA increases account security.