ALERT: NEW SCAMS IMPERSONATING GOOGLE MEET AND GMAIL

Google's Gmail service already has more than 2500 billion users worldwide, making it the most used email service globally. This makes the platform a target for scammers seeking to optimize phishing and social engineering techniques by combining them to deceive.
Through spoofing techniques involving widely trusted platforms such as Google Meet and Gmail, cybercriminals are executing strategies that put the confidentiality of personal and corporate data at risk.
A malware campaign, designed to mimic Google Meet pages, attempts to trick users with connectivity error messages that induce them to run malicious code on their systems, on both Windows and macOS.
These messages redirect to fake URLs such as:

  • meet[.]google[.]us-join[.]com
  • meet[.]google[.]web-join[.]com
  • meet[.]google[.]com-join[.]us

These domains are traps that install malware capable of stealing sensitive information, affecting both individuals and organizations.
On the other hand, an advanced, AI-powered phishing scheme has been using Gmail to extract credentials from unsuspecting users. This sophisticated campaign includes fake account recovery emails, followed by fraudulent login pages that mimic Google's authenticity. In extreme cases, victims have reportedly received calls that appear to be from Google support, increasing the likelihood that people will fall for the scam by believing they are interacting with a legitimate entity.
To protect against these attacks, it is essential to maintain rigorous verification practices.

  • Avoid clicking on links from unverified senders
  • Never copy and paste code from dubious sources
  • Verifying all official invitations and communications directly with the original source are essential steps.
  • If you receive a message from someone claiming to be from Google, it is recommended to verify the authenticity of the email and the domain, and not to provide confidential information over the phone or through unverified links.