Blog

Inside the SOC

New technique to deliver malicious email payloads: Webmail login portal hidden within Google Translate domain

New technique to deliver malicious email payloads: Webmail login portal hidden within Google Translate domainDefault blog imageDefault blog image
04
Nov 2022
04
Nov 2022

Introduction

Darktrace recently detected a new technique used by threat actors to deliver malicious email payloads. The malicious link was observed hidden within a legitimate domain, namely Google Translate services. To understand its abusive capabilities, it is important to first understand a benign case of how these links are created.  

Google often provides a ‘Translate this page’ option for sites written in a different language to the default browser language.

Figure 1- A google search result for an international company E.g ‘Crédit Agricole’ gives the option to translate the page from French to English.

Figure 2- When clicked, the browser displays a link with a translate[.]goog domain, and the original domain, credit-agricole[.]fr, becomes the link’s subdomain.


When this feature is exploited by threat actors it can be particularly dangerous, as legacy security products that rely on ‘known’ or ‘safe’ domain-based detection are likely to register these emails as safe and provide no protective actions. If a recipient were to click on the malicious link, they could risk losing their credentials or even compromising their machine. 

 In contrast, Darktrace/Email has been able to consistently identify and action emails from such campaigns. This blog will discuss one of these events.

The Campaign 

The apparent motive in this attack was to harvest credentials and/or deploy malware on the recipient’s device. Credential harvesting can lead to the sale of credentials on the dark web, or the attacker may choose to leverage those credentials in subsequent attacks. Both harvesting credentials and deploying malware have severe potential ramifications, including but not limited to sensitive company data leaks and financial loss. 

During this attack, the threat actor sent similar emails to a group of recipients in a short space of time. The recipients were not normally associated with each other and Darktrace swiftly identified them as unsolicited bulk mail. The new technique that was leveraged included using Google’s translate services to share malicious links using legitimate seeming domains. The malicious host was visible within the subdomain ‘636416-selcdn-ru[.]translate[.]goog’.  

When clicked, the link displays a google translate page stating, “Can’t translate this page”. There is then a hyperlink, “Go to original page”, that brings the user to the malicious host- 636416[.]selcdn[.]ru. Finally, the host displays a fake webmail portal login. If a user engages, the attacker can harvest their credentials to either sell or use in subsequent attacks.

Figure 3- The Google Translate page that is displayed once clicking on the full link within the email. The hyperlink at the bottom of the image is where the user is redirected by clicking “Go to original page”. It is there that the fake webmail portal login is then displayed. 

Darktrace Coverage 

As the malicious emails contained links to ‘safe’ Google Translate domains, most email security products would not characterize the links as suspicious. However, Darktrace/Email levies hundreds of metrics to identify whether emails belong in a recipient’s inbox. In this case Darktrace highlighted anomalies including rare subdomains, links containing unknown redirects, emails from spoofed freemail accounts and senders that had sent a relatively large number of emails within a short time frame. Furthermore, the attacker had never sent any previous emails to the organization prior to this email campaign. 

On top of providing visibility, the RESPOND function of Darktrace/Email took action autonomously and instantaneously without any human confirmation required. These actions included locking links and holding malicious emails. 

Figure 4- Darktrace/Email overview tab shows the Anomaly Indicators section as well as the History, Association, and Validation information of this sender.

Figure 5 - The Darktrace RESPOND/Email model tab displays all models that triggered on the email and the associated actions. The most severe delivery action supersedes the others, so here the email was held. 

Concluding Thoughts 

Threat actors are continuously updating the way they deliver malicious payloads within emails. While this particular email campaign utilized Google Translate domains to hide malicious links, subsequent attacks may well be seen leveraging other legitimate domains. Companies are only as strong as their weakest link; a single compromised internal email account can be used to send phishing emails to internal recipients, collect sensitive company information, inject malware onto the device, and more. Security tools must evolve to focus on anomalies within the email, rather than relying on rules or signatures of previously seen attacks. Furthermore, email tools must be able to autonomously respond as soon as the malicious emails enter the company’s environment. Only with these precautions will the risks associated with malicious emails be mitigated. 

Thanks to Steven Haworth and Steven Sosa for their contributions.

Appendices 

Relevant Darktrace Model Detections

·      Association / Anomalous Association

·      Association / New Sender

·      Association / Unknown Sender

·      Association / Unlikely Recipient Association

·      High Antigena Anomaly [part of the RESPOND functionality]

·      Link / Low Link Association

·      Link / Low Link Association and Unknown Sender

·      Link / New Correspondent Classified Link

·      Link / New Unknown Redirect

·      Link / Open Redirect

·      Link / Visually Prominent Link

·      Spam / Unsolicited Bulk Mail

·      Spoof / Spoofed Freemail

·      Unusual / New Sender Wide Distribution

·      Unusual / Sender Surge

More in this series:

항목을 찾을 수 없습니다.

Like this and want more?

Receive the latest blog in your inbox
감사합니다! 제출되었습니다!
양식을 제출하는 동안 문제가 발생했습니다.
INSIDE THE SOC
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
AUTHOR
ABOUT ThE AUTHOR
Rachel Resnekov
Cyber Analyst
PRODUCT SPOTLIGHT
항목을 찾을 수 없습니다.
COre coverage
항목을 찾을 수 없습니다.
This Article
New technique to deliver malicious email payloads: Webmail login portal hidden within Google Translate domain
Share
Twitter logoLinkedIn logo

귀하의 비즈니스에 좋은 소식입니다.
나쁜 사람들에게 나쁜 소식입니다.

무료 평가판 시작

무료 평가판 시작

유연한 배송
가상환경에 설치하거나 하드웨어에 설치할 수 있습니다.
빠른 설치
설치하는 데 1 시간 밖에 걸리지 않으며 이메일 보안 평가판의 경우 더 적게 걸립니다.
여정 선택
클라우드, 네트워크 또는 이메일을 포함하여 가장 필요한 곳 어디에서나 셀프 러닝 AI를 사용해 보십시오.
약정 없음
Darktrace Threat Visualizer 및 세 개의 맞춤형 위협 보고서에 대한 모든 액세스 권한이 있으며 구매 의무는 없습니다.
For more information, please see our Privacy Notice.
감사합니다! 제출되었습니다!
양식을 제출하는 동안 문제가 발생했습니다.

Get a demo

유연한 배송
가상환경에 설치하거나 하드웨어에 설치할 수 있습니다.
빠른 설치
설치하는 데 1 시간 밖에 걸리지 않으며 이메일 보안 평가판의 경우 더 적게 걸립니다.
여정 선택
클라우드, 네트워크 또는 이메일을 포함하여 가장 필요한 곳 어디에서나 셀프 러닝 AI를 사용해 보십시오.
약정 없음
Darktrace Threat Visualizer 및 세 개의 맞춤형 위협 보고서에 대한 모든 액세스 권한이 있으며 구매 의무는 없습니다.
감사합니다! 제출되었습니다!
양식을 제출하는 동안 문제가 발생했습니다.