Site navigation

Gmail Hack Putting Accounts at Risk

David Paul

,

Gmail hack
A ransomware group has already hacked into a small number of Gmail accounts with Google claiming an attacker could read all email messages.

Google has released a new report warning of an email hack targeting a small number of common Gmail accounts in Iran.

The firm’s Threat Analysis Group (TAG) revealed that an espionage threat group under the name Charming Kitten, backed by the Iranian Government, has developed a tool that has been used to successfully hack a small number of Gmail user accounts.

Writer of the report, Ajax Bash from TAG, said that the HYPERSCRAPE tool has been confirmed to have been “used to steal user data from Gmail, Yahoo!, and Microsoft Outlook accounts”.

According to Bash, the tool has already been used to successfully compromise Gmail accounts – and has the potential to be used on a larger scale.

Bash commented: “We have seen it deployed against fewer than two dozen accounts located in Iran.” He added that Google had notified the affected users and “taken actions to re-secure these accounts”.


What is HYPERSCRAPE?

The tool was first detected by Google TAG researchers in December 2021, although further investigation revealed the oldest attack seems to date to 2020.

The Google Gmail hack spoofs the user agent to look like an outdated web browser, enabling the basic HTML view in Gmail. Once logged in, the tool changes the account’s language settings to English and iterates through the contents of the mailbox, individually downloading messages as .eml files and marking them unread.


Recommended


Once finished downloading the inbox, it reverts the language back to its original settings and deletes any security emails from Google.

Bash said that earlier versions of HYPERSCRAPE contained the option to request data from Google Takeout, a feature which allows users to export their data to a downloadable archive file.

Targets of the HYPERSCRAPE tech were carefully selected, Bash said, adding that so far, only a handful of Iran-based users are known to have been compromised.

Additionally, Bash said that, for HYPERSCRAPE to be executed, the attackers need to have already acquired the victim’s user credentials, reducing the chances that everyday users will be affected.


How to protect yourself

The discovery has been made public to “raise awareness on bad actors like Charming Kitten within the security community,” Bash commented, as well as for the high-risk individuals and firms that could be targeted by the threat group.

Google has said that anyone that falls into these categories should join the Advanced Protection Program (APP) as well as make use of Google Account Level Enhanced Safe Browsing.

Additionally, updating weak passwords and adding two-factor authentication to all accounts is a strong way of protecting yourself right now.

Google suggested that users remain security-minded despite being at low risk of falling victim to HYPERSCRAPE. Password reset links coming to your email, details of bank accounts, and personal data can be avoided by ensuring a better basic security posture.


Get the latest news from DIGIT direct to your inbox

Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.

To subscribe, click here.

David Paul

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data