, 8 tweets, 3 min read
My Authors
Read all threads
Was the target of a fairly sophisticated multi-vector spearphishing attack yesterday. Started with multiple calls from a US number, with pre-recorded messages from an American accented woman's voice saying my Google account login had failed.
As soon as I disconnected the call, I received cleanly formatted SMSes from a shortcode number, saying I needed to reauthenticate. There was a link, to a goo.gl shortcode.
Out of curiosity, I opened the shortcode from a different device. Which led to this fairly sophisticated page.
Notice how my name and email id are hard-coded into the login page, to make it look as though they were pre-filled in from earlier login sessions. But here's the thing, I do not sign in to Google services except from one browser. So I knew these were hard-coded.
The URL of course was another giveaway. But given that most lay users do not bother to read URLs and many browsers increasingly hide URLs as unnecessary detail, I wonder how many will notice.
The site's security certificate was valid too. Using a Letsencrypt cert. Look at the various subdomains it uses to target people.
Lastly, when I entered my true password, "thisisasecretpasswordpleasedonotshare1234", it threw up a very real looking error message. Presumably to get me to reenter my password.
To recap, multiple international phone calls followed by multiple SMSes followed by hard-coded login pages with my name and email id. They had my name, email id, phone number etc. This was targeted. I wonder why, and I wonder who. /Fin.
Missing some Tweet in this thread? You can try to force a refresh.

Enjoying this thread?

Keep Current with Rohin Dharmakumar

Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

Twitter may remove this content at anytime, convert it as a PDF, save and print for later use!

Try unrolling a thread yourself!

how to unroll video

1) Follow Thread Reader App on Twitter so you can easily mention us!

2) Go to a Twitter thread (series of Tweets by the same owner) and mention us with a keyword "unroll" @threadreaderapp unroll

You can practice here first or read more on our help page!

Follow Us on Twitter!

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just three indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3.00/month or $30.00/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!