This sneaky malware hijacks Google Forms to demand money in nasty phishing scheme
A new version of BazarCall, a phishing attack designed to take money from victims, has been observed, this time hijacking Google Forms to generate fake payment receipts in order to make malicious phishing attacks look more legitimate.
The attack gets its name from the way it manipulates victims to engage with the threat actor, sometimes by means of phone call.
The alert, raised by Abnormal Security, reveals the latest wave of BazarCall attacks after they first became popular in 2020.
Watch out for that strange receipt
The campaign begins with a phishing email that looks like a receipt for a payment or subscription. Abnormal Security says that supposed charges range from $49.99 to over $500 – pretty significant amounts that are designed to raise alarm bells for victims.
The group has been observed impersonating dozens of high-profile companies, including Netflix, Hulu, Disney+, McAfee, and Norton.
The sense of urgency pushed onto the victim then pressures them into calling a number displayed in the email to dispute the charge.
The attacker uses Google Forms to create a fake invoice, using details like invoice numbers, payment methods, and the product or service. They then enter the victim’s email address into one of the fields which prompts a receipt to be sent to the victim.
This way, the email comes from a google.com domain, helping to evade detection by improving the sense of legitimacy.
The goal is for the group to gain access to an organization’s assets by tricking the recipient into installing malware.
Abnormal Security says that legacy security tools like secure email gateways are no longer capable of keeping up with these more advanced attack methods. With it being 2023, it should come as no surprise that artificial intelligence is being suggested as the solution.
The company says that AI-native solutions would be able to use ML to identify this email as an attack. Clearly, more creative and novel attacks are demanding a revised approach to security as we know it today.
More from TechRadar Pro
A new version of BazarCall, a phishing attack designed to take money from victims, has been observed, this time hijacking Google Forms to generate fake payment receipts in order to make malicious phishing attacks look more legitimate. The attack gets its name from the way it manipulates victims to engage…
Recent Posts
- You don’t need to spend a fortune on good audio — these 20 headphones under AU$100 have hundreds of 5-star user reviews
- Nintendo confirms it will sell a new Switch 2 with replaceable battery in the EU
- Apple begins requiring age verification for App Store use in Texas
- The co-creator of Scavengers Reign is working on a new show for Netflix
- Apple is bringing age verification to Texas this week
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023