More than 75 widely known brands, including MasterCard, Uber, Unilever, and Disney, have been spoofed in fraudulent Calendly invites as part of an ongoing phishing attack campaign aimed at pilfering Google Workspace and Business account credentials, BleepingComputer reports.
Illicit emails purporting to be from recruiters for popular brands include a link that redirects to a bogus Calendly landing page with a CAPTCHA, which subsequently leads to an adversary-in-the-middle phishing page for Google Workspace login session compromise, according to a Push Security analysis. Other variants of the scheme targeted Business credential theft and both Google and credential exfiltration via Browser-in-the-Browser attacks, said researchers, who discovered multiple anti-analysis mechanisms integrated into the phishing pages.
Another Push Security report revealed that Google Ads Manager accounts have been subjected to a malvertising campaign involving a nefarious "Google Ads" ad result on Google , which redirected to a Google login screen-spoofing AiTM page.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
