
Millions of Google users are getting a warning from Check Point security researchers this week who have identified a new attack method which uses a combination of Google Calendar, Drawings, Forms and Gmail in an attempt to phish users and bypass email security policies.
As reported by Forbes, attacks using this method have been employed roughly 2,300 times over the course of a two week period. The threat actors behind them started by modifying sender headers to make emails appear that they were sent through Google Calendar from a known and legitimate individual. Initially, this method was used to exploit the features within Google Calendar to link to malicious Google Forms, then evolved to align with the capabilities of Google Drawings after it was realized that security products were able to flag these malicious calendar invites.