21/12/2023
Cybercriminals use Google Forms to fake credibility ๐
BazaCall, first observed in 2020, launched phishing attacks with emails impersonating legitimate subscription notices (such as Netflix and Disney+), encouraging users to contact support desk to avoid a $50 to $500 charge.
Responses to the Google Form are sent from 'forms-receipts-noreply@google[.]com', which is both:
โ๏ธ A trusted domain
โ๏ธ Has a higher chance of bypassing secure email gateways
Stay cautious and read the article below to learn more.
BazaCall phishing attacks are evolving. Threat actors now use Google Forms to appear more credible.