'
Breaking
May 12, 2025

Beware, hackers can apparently now send phishing emails from “no-reply@google.com” | usagoldmines.com


  • Crooks are abusing Google’s notification system to bypass email protection
  • Through OAuth apps, they are able to generate convincing phishing emails
  • The campaign also uses sites.google.com

Researchers have discovered a clever and elaborate phishing scheme that abused Google’s services to trick people into giving away their credentials for the platform.

Lead developer of the Ethereum Name Service, Nick Johnson, recently received an email that seemed to have come from no-reply@google.com. The email said that law enforcement subpoenaed Google for content found in his Google Account.

He said that the email looked legitimate, and that it was very difficult to spot that it’s actually fake. He believes less technical users might very easily fall for the trick.

Get Keeper Personal for just $1.67/month, Keeper Family for just $3.54/month, and Keeper Business for just $7/month

​Keeper is a cybersecurity platform primarily known for its password manager and digital vault, designed to help individuals, families, and businesses securely store and manage passwords, sensitive files, and other private data.

It uses zero-knowledge encryption and offers features like two-factor authentication, dark web monitoring, secure file storage, and breach alerts to protect against cyber threats.

Preferred partner (What does this mean?)View Deal

DKIM signed

Apparently, the crooks would first create a Google account for me@domain. Then, they would create a Google OAuth app, and put the entire phishing message (about the fake subpoena) in the name field.

Then, they would grant themselves access to the email address in Google Workspace.

Google would then send a notification email to the me@domain account, but since the phishing message was in the name field, it would cover the entire screen.

Scrolling to the bottom of the email message would show clear signs that something was amiss, since at the bottom one could read about getting access to the me@domain email address.

The final step is to forward the email to the victim. “Since Google generated the email, it’s signed with a valid DKIM key and passes all the checks,” Johnson explained how the emails landed in people’s inbox and not in spam.

The attack is called a “DKIM replay phishing attack,” since it leans on the fact that in Google’s systems, DKIM checks only the message and the headers, not the envelope. Since the crooks first registered the me@domain address, Google will show it as if it was delivered to their email address.

To hide their intentions even further, the crooks used sites.google.com to create the credential-harvesting landing page. This is Google’s free web-building platform and should always raise red flags when spotted.

Via BleepingComputer

You might also like

​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

NASA calculated when life will end on Earth. It doesn’t look good | usagoldmines.com

Use 'Noir' to Force Dark Mode in Safari Justin Pot | usagoldmines.com

The Five Best Egg Replacements I've Used for Baking (so Far) Allie Chanthorn Reinmann | usagoldmines...

How a designer turned an iPad and Apple Pencil into the heart of a creative business jacob.krol@futu...

Google's new AI video feature is rolling out on another company's smartphones erichs211@gmail.com (E...

Copyright Office head fired after reporting AI training isn’t always fair use Ashley Belanger | usag...

FCC Republican wants to “DOGE the FCC,” give money to Elon Musk’s Starlink Jon Brodkin | usagoldmine...

Score HP’s OLED gaming laptop with RTX 4060 for $470 off today | usagoldmines.com

Microsoft shows off the cool Windows Start concepts we never got | usagoldmines.com

iOS 19 Will Include AI Battery Management Feature Juli Clover | usagoldmines.com

I use this ingenious $21 USB-C gadget weekly. It’s a game-changer | usagoldmines.com

The best monitors: 11 top picks for gaming, 4K, HDR, and more | usagoldmines.com

Best USB-C hubs and dongles: Add ports to your laptop or tablet | usagoldmines.com

Why You Need Multiple Savings Accounts Meredith Dietz | usagoldmines.com

What You Should Hoard Before Tariff Price Increases Kick In Jeff Somers | usagoldmines.com

Get $100 Off Nearly Every M3 iPad Air on Amazon, Available From $499 Mitchel Broussard | usagoldmine...

Apple's C1 Modem Gets First Security Update in iOS 18.5 Juli Clover | usagoldmines.com

Google Messages is getting another wave of updates – here are 7 you can expect to see soon rowan.dav...

Are you due a payout from Apple's $95 million Siri settlement? Here's how to claim mark.wilson@futur...

Galaxy Z Flip 7 Cover Screen Should Cover the Entire Front, Says Leak Kellen | usagoldmines.com

The First Smartphone to Get Google's AI Video Generator Isn't a Pixel Jake Peterson | usagoldmines.c...

Apple Releases tvOS 18.5 Juli Clover | usagoldmines.com

Apple Releases visionOS 2.5 With Vision Tab for Apple TV App Juli Clover | usagoldmines.com

Apple Releases watchOS 11.5 With New Pride Watch Face Juli Clover | usagoldmines.com

Apple Releases iOS 18.5 With New Wallpaper, Screen Time Changes, Carrier Satellite Support for iPhon...

Apple Releases macOS Sequoia 15.5 Juli Clover | usagoldmines.com

CPU microcode hack could infect processors with ransomware directly | usagoldmines.com

What is the release date and time for Star Wars: Andor season 2 episodes 10 to 12 on Disney+? tom.po...

German consumer protection group calls on Meta to halt its AI training in the EU – will other countr...

Samsung Galaxy S25 Edge launch live: all the last-minute Unpacked news ahead of the event | usagold...

FTC and DOJ push for data protection in Google antitrust case | usagoldmines.com

New pope chose his name based on AI’s threats to “human dignity” Benj Edwards | usagoldmines.com

Samsung’s new OLED gaming monitor is 500Hz and crazy expensive | usagoldmines.com

Razer releases head cushion with built-in spatial wireless speakers | usagoldmines.com

Microsoft Teams will let hosts block screenshots and recordings soon | usagoldmines.com

Ooh Look, a New Google Logo! Kellen | usagoldmines.com

My Favorite Amazon Deal of the Day: The Peloton Bike and Bike+ Daniel Oropeza | usagoldmines.com

Apple TV+ Announces New Series From Celebrity Chef Gordon Ramsay Joe Rossignol | usagoldmines.com

Boost iPhone Audio Features With This Simple Bluetooth Tip Tim Hardwick | usagoldmines.com

US and China pause tariffs for 90 days as Trump claims “historic trade win” Jon Brodkin | usagoldmin...

Germ-theory skeptic RFK Jr. goes swimming in sewage-tainted water Beth Mole | usagoldmines.com

How to stop CCleaner from launching with Windows | usagoldmines.com

U.S. reduces China tariffs from 145% to 30%, for now | usagoldmines.com

A hacker is demanding money to keep your kids’ data safe. It won’t work | usagoldmines.com

Welp, Nvidia’s RTX 5090 can crack an 8-digit password in 3 hours | usagoldmines.com

Microsoft is testing a new ‘Advanced Settings’ page in Windows | usagoldmines.com

Microsoft is now squeezing Copilot AI into its app store | usagoldmines.com

The Best Ways to Protect Your Strawberries From Pests and Disease Amanda Blum | usagoldmines.com

Beware These REAL ID Scams Emily Long | usagoldmines.com

Watch the New Trailer for Apple's Big Summer Movie Starring Brad Pitt Joe Rossignol | usagoldmines.c...

Anker Offers MacRumors Readers 20% Off Collection of Chargers, Hubs, Batteries, and More Mitchel Bro...

The Nvidia Shield is getting 120fps cloud gaming support, but with a big catch | usagoldmines.com

I can't decide if Pro-Ject's new turntable with Charlie Brown's head on the platter is cute or creep...

I saw Panasonic’s 2025 TV lineup in person, and here are the 3 models you should be most excited for...

OpenAI and Microsoft in talks to revise terms and renew partnership, FT reports | usagoldmines.com

Mercedes-AMG just teased its 1,000bhp Porsche Taycan Turbo GT rival –and it'll need to dip deep into...

Sony’s next Alpha camera gets rumored launch date – and it could have an unusual EVF feature | usag...

Google to pay $1.4 billion in unauthorized biometric data collection and geo-tracking lawsuits | us...

Nintendo warns that it can brick Switch consoles if it detects hacking, piracy Kyle Orland | usagold...

Grab Samsung’s ultra-tiny 128GB flash drive for only $15 right now | usagoldmines.com

Today’s best laptop deals: Save big on work, school, home use, and gaming | usagoldmines.com

This Apple Watch Series 10 Is at Its Lowest Price Right Now Pradershika Sharma | usagoldmines.com

The Out-of-Touch Adults' Guide to Kid Culture: YouTube's Animated Kitten Horror Stephen Johnson | us...

How to Update Your Computer’s BIOS or UEFI (and When You Should) David Nield | usagoldmines.com

Apple Shares Spooky 'Mac to School' Ads Highlighting AirDrop and More Joe Rossignol | usagoldmines.c...

iOS 18.5 Expected This Week With These New Features Joe Rossignol | usagoldmines.com

These North Korean IT workers have been infiltrating Western businesses since 2016 | usagoldmines.c...

Nvidia’s gaming GPUs could still get pricier despite tariffs truce, new report claims – here’s why ...

Fortnite players can get 20% back on V-Buck purchases by using Epic's payment system, giving you mas...

NYT Connections hints and answers for Tuesday, May 13 (game #702) | usagoldmines.com

NYT Strands hints and answers for Tuesday, May 13 (game #436) | usagoldmines.com

This DOGE workers' credentials have allegedly been exposed by infostealing malware | usagoldmines.c...

Quordle hints and answers for Tuesday, May 13 (game #1205) | usagoldmines.com

"A win for privacy" – Florida rejects the encryption backdoor law for social media chiara.castro@fut...

Spotify's iPhone app will soon get a useful upgrade for audiobooks fans – here's what's coming rowan...

Five considerations for UK government AI success | usagoldmines.com

Seawater’s role in surfing the AI wave | usagoldmines.com

A new era in cancer therapies is at hand Claudia López Lloreda, Undark Magazine | usagoldmines.com

This Ryzen 7 mini PC with 32GB RAM is down to its lowest ever price | usagoldmines.com

I punished this Bluetooth speaker for a year. It just won’t die | usagoldmines.com

Why I Always Roast My Rhubarb Allie Chanthorn Reinmann | usagoldmines.com

Most businesses can't fill cyber roles leaving huge gaps in defense | usagoldmines.com

Outdated and unsecured IoT devices are a serious risk for UK businesses | usagoldmines.com

I suggest streaming these 3 movies with great Rotten Tomatoes ratings before they leave Prime Video ...

Forget the Nintendo Switch 2 – MSI’s surprise new Steam Deck rival could be the handheld gaming devi...

Freepik launches new enterprise AI plan - but is it enough to tackle Adobe’s dominance in the field?...

10 Podcasts for People Who Love (and Miss) 'Heavyweight' Lauren Passell | usagoldmines.com

Suits spin-off has been canceled even though the original was one of the most-streamed shows of all ...

Windows 11 gets more AI upgrades we didn’t ask for – as Copilot pops up on the desktop and Microsoft...

AllTrails is the latest app with an AI-powered subscription tier – but it looks way more useful than...

Laptop processors are better than ever, but I still don’t give a hoot about ‘AI PCs’ - and neither s...

This Microsoft 365 phishing campaign can bypass MFA - here's what we know | usagoldmines.com

Marvel Rivals tier list: my picks for the best characters to use in Season 2 after playing hundreds ...

Ditching your gaming PC’s case isn’t as crazy as it sounds | usagoldmines.com

Windows Defender isn’t just PC antivirus. Here are all the ways it protects you | usagoldmines.com

WSJ: Apple Considering Price Increases for iPhone 17 Lineup Tim Hardwick | usagoldmines.com

AirPods and Apple Watch Models to Get Tiny AI Cameras in 2027 Tim Hardwick | usagoldmines.com

iOS 19 Likely to Sync Captive Wi-Fi Data Between Devices Tim Hardwick | usagoldmines.com

Peacemaker season 2 finally has a teaser trailer – here are 3 things you need to know | usagoldmine...

One of AMD's Radeon RX 9060 XT partner GPUs has been leaked online - I just hope the $566 price tag ...