Job scam uses fake Google Forms site to harvest Google logins
嗯,用户让我帮忙总结一篇文章,控制在100字以内,而且不需要特定的开头。首先,我需要仔细阅读文章内容,理解其主要信息。 文章讲的是一个以工作为主题的钓鱼活动调查。他们发现了一些可疑的URL,看起来像是模仿Google Forms的。这些链接被重定向到本地Google搜索网站,这是钓鱼者常用的策略。他们还找到了一个生成链接的PHP脚本,用于创建个性化URL。 钓鱼页面看起来像Google Forms,收集个人信息和简历内容。点击登录按钮会跳转到另一个钓鱼网站,要求输入Google账户凭证。文章还提到这些链接可能是通过LinkedIn或电子邮件分发的,并给出了防范建议。 总结的时候,我需要涵盖钓鱼活动、仿冒Google Forms、收集信息、重定向到恶意网站以及防范建议这几个关键点。同时要控制在100字以内,语言简洁明了。 可能的结构是:描述钓鱼活动、仿冒手段、收集的信息、重定向和防范措施。确保每个部分都简明扼要,不遗漏重要信息。 最后检查字数是否符合要求,并确保表达清晰。 </think> 文章描述了一个伪装成Google Forms的钓鱼活动,利用“招聘机会”主题引诱用户点击可疑链接。这些链接被重定向到恶意网站,试图窃取用户信息和Google账户凭证。研究人员发现生成这些链接的脚本,并指出此类攻击常见于求职相关的钓鱼邮件或LinkedIn消息中。建议用户提高警惕,避免点击不明链接,并使用安全工具防范此类威胁。 2026-2-18 12:22:22 Author: www.malwarebytes.com(查看原文) 阅读量:0 收藏

As part of our investigation into a job-themed phishing campaign, we came across several suspicious URLs that all looked like this:

https://forms.google.ss-o[.]com/forms/d/e/{unique_id}/viewform?form=opportunitysec&promo=

The subdomain forms.google.ss-o[.]com is a clear attempt to impersonate the legitimate forms.google.com. The “ss-o” is likely introduced to look like “single sign-on,” an authentication method that allows users to securely log in to multiple, independent applications or websites using one single set of credentials (username and password).

Unfortunately, when we tried to visit the URLs we were redirected to the local Google search website. This is a common phisher’s tactic to prevent victims from sharing their personalized links with researchers or online analysis.

After some digging, we found a file called generation_form.php on the same domain, which we believe the phishing crew used to create these links. The landing page for the campaign was: https://forms.google.ss-o[.]com/generation_form.php?form=opportunitysec

The generation_form.php script does what the name implies: It creates a personalized URL for the person clicking that link.

With that knowledge in hand, we could check what the phish was all about. Our personalized link brought us to this website:

Fake Google Forms site
Fake Google Forms site

The greyed out “form” behind the prompt promises:

  • We’re Hiring! Customer Support Executive (International Process)
  • Are you looking to kick-start or advance your career…
  • The fields in the form: Full Name, Email address, and an essay field “Please describe in detail why we should choose you”
  • Buttons: “Submit” and “Clear form.”

The whole web page emulates Google Forms, including logo images, color schemes, a notice about not “submitting passwords,” and legal links. At the bottom, it even includes the typical Google Forms disclaimer (“This content is neither created nor endorsed by Google.”) for authenticity.

Clicking the “Sign in” button took us to https://id-v4[.]com/generation.php, which has now been taken down. The domain id-v4.com has been used in several phishing campaigns for almost a year. In this case, it asked for Google account credentials.

Given the “job opportunity” angle, we suspect links were distributed through targeted emails or LinkedIn messages.

How to stay safe

Lures that promise remote job opportunities are very common these days. Here are a few pointers to help keep you safe from targeted attacks like this:

  • Do not click on links in unsolicited job offers.
  • Use a password manager, which would not have filled in your Google username and password on a fake website.
  • Use an up to date, real-time anti-malware solution with a web protection component.

Pro tip: Malwarebytes Scam Guard identified this attack as a scam just by looking at the URL.

IOCs

id-v4[.]com

forms.google.ss-o[.]com

forms.google.ss-o.com blocked by Malwarebytes
Blocked by Malwarebytes

We don’t just report on scams—we help detect them

Cybersecurity risks should never spread beyond a headline. If something looks dodgy to you, check if it’s a scam using Malwarebytes Scam Guard. Submit a screenshot, paste suspicious content, or share a link, text or phone number, and we’ll tell you if it’s a scam or legit. Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.

About the author

Was a Microsoft MVP in consumer security for 12 years running. Can speak four languages. Smells of rich mahogany and leather-bound books.


文章来源: https://www.malwarebytes.com/blog/scams/2026/02/job-scam-uses-fake-google-forms-site-to-harvest-google-logins
如有侵权请联系:admin#unsafe.sh