Google flags sophisticated Gmail phishing attack against India and others
Google team observed a large-scale attack of a credential phishing campaign targeting more than 12,000 Gmail accounts by this threat actor.
Stay updated with breaking news from Feitian Multipass. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.
Google team observed a large-scale attack of a credential phishing campaign targeting more than 12,000 Gmail accounts by this threat actor.
The vulnerability allows threat actors to recover the encryption key used by the hardware security key to generate cryptographic tokens for two-factor authentication (2FA) operations. Once obtained, the two security researchers say the ECDSA private key would allow threat actors to clone Titan, YubiKey, and other keys to bypass 2FA procedures. Attack requires physical access However, while the attack sounds disastrous for Google and Yubico security key owners, its severity is not what it seems. In a 60-page PDF report, Victor Lomne and Thomas Roche, researchers with Montpellier-based NinjaL...