Domain NAMEAM.com for sale! This premium domain is available now at Kadomain.com

Urgent warning to billions of Gmail users over dangerous 'no-reply' attack

  • unilad.com language
  • 2025-05-21 23:42 event
  • 2 weeks ago schedule
A tech expert has broken down 'clues' within a sophisticated phishing email which has been sent to Gmail users from a 'valid, signed email'. Founder of Ethereum Name Service, Nick Johnson, took to Tw

A tech expert has broken down 'clues' within a sophisticated phishing email which has been sent to Gmail users from a 'valid, signed email'.

Founder of Ethereum Name Service, Nick Johnson, took to Twitter last month to raise awareness of 'an extremely sophisticated phishing attack' explaining it 'exploits a vulnerability in Google's infrastructure'.

And given cybersecurity company Kaspersky shared an article about it last week, it would seem the attack is ongoing - UNILAD has contacted Google for comment.

Johnson took to Twitter on April 16 to share screenshots of the email he received, analysing the images explaining just how advanced the phishing attack is.

Have you received an email from no-reply@google.com? (Illustration by Mateusz Slodkowski/SOPA Images/LightRocket via Getty Images)

What does the 'no-reply' phishing email looks like?

The 'first thing to note'? A 'valid, signed email'.

"It really was sent from no-reply@google.com," he explains. "It passes the DKIM signature check, and GMail displays it without any warnings - it even puts it in the same conversation as other, legitimate security alerts."

Not only this, but the 'Sites link' then takes you to 'a very convincing 'support portal' page', which has a domain which looks 'legit' too.

Should you then click on 'Upload additional documents' or 'View case', you'd also be taken to a 'signin page' which is 'an exact duplicate of the real thing'.

"The only hint it's a phish is that it's hosted on http://sites.google.com instead of http://accounts.google.com," he adds.

Johnson theorized the scam works in 'harvest[ing] your login credentials' should you put them in and then 'use them to compromise your account'.

Unsurprisingly, he didn't go further to check.

But how was the phishing attack able to make itself look so believable?

The phishing email is seriously advanced (Twitter/ @nicksdjohnson)

How does the phishing 'no-reply' email look so 'convincing'?

Essentially, the phishers register a domain, create a Google account for 'me@domain' and then create a Google OAuth application where they enter the Phishing message alongside some whitespace and 'Google Legal Support'.

"Now they grant their OAuth app access to their 'me@...' Google account. This generates a 'Security Alert' message from Google, sent to their 'me@...' email address. Since Google generated the email, it's signed with a valid DKIM key and passes all the checks," Johnson explains.

The scammers then 'forward the message to their victims' and 'because DKIM only verifies the message and its headers and not the envelope, the message passes signature validation and shows up as a legitimate message in the user's inbox - even in the same thread as legit security alerts'.

"Because they named their Google account 'me@', GMail shows the message was sent to 'me' at the top, which is the shorthand it uses when a message is addressed to your email address - avoiding another indication that might send up red flags," he resolves.

And how this is possible? Well, Johnson argues it's down to 'two vulnerabilities in Google's infra[structure]'.

The email was 'really sent from no-reply@google.com' (Twitter/ @nicksdjohnson)

The 'two vulnerabilities in Google infrastructure'

Johnson explains the 'fake portal is fairly straightforward' as users can 'host content on a http://google.com subdomain'.

Johnson says there's 'no way to report abuse from the Sites interface too', meaning it's easier for the phishers to simply upload new versions of 'arbitrary scrips and embeds'.

Johnson recommends Google 'disable scrips and arbitary embeds in Sites' as they're 'too powerful a phishing vector'.

However, he notes the email is 'much more sophisticated'.

So, how did Johnson spot it was dodgy?

The white space is reportedly a clue something's phishy (Twitter/ @nicksdjohnson)

How to spot a phishing email

Johnson points out the 'first clues' come with the header of the email.

"Although it was signed by http://accounts.google.com, it was emailed by http://privateemail.com, and sent to 'me@blah,'" he states.

And the 'second clue'? "Below the phishing message is a lot of whitespace (mostly not shown) followed by 'Google Legal Support was granted access to your Google Account' and the odd me@... email address again," Johnson flags.

Johnson notes he's submitted a bug report to Google, later updating Google responded saying it 'will be fixing the oauth bug'.

257. Holiday hotspot loved by Brits has strict new law resulting in £1,250 fine for wearing bikini or swim shorts

  • 2 weeks ago schedule
  • ladbible.com language

Nothing beats a good summer holiday abroad. Chilling by the pool with a pint, or taking a stroll through the town while getting gloriously tanned in your bikini.Well, there's some bad news I'm afraid

258. Doctor reveals simple 'pen and paper' test which could detect early signs of dementia before diagnosis

  • 2 weeks ago schedule
  • unilad.com language

A simple test requiring just a pen and paper could reveal if someone close to you has dementia - before having been diagnosed.A doctor specializing in the degenerative disease has taken to his YouTub

259. Engaged couple dies in separate crashes minutes apart leaving behind 4-year-old son

  • 2 weeks ago schedule
  • unilad.com language

A couple set to be wed next year have passed away following two separate 'tragic' car accidents on the same Louisiana high road, leaving behind their four-year-old son. On May 16, Louisiana State Pol

260. How much Jeremy Clarkson has reportedly been paid by Amazon Prime for Clarkson's Farm

  • 2 weeks ago schedule
  • ladbible.com language

Ahead of the release of season four of Clarkson’s Farm, many fans will be curious just how much Jeremy Clarkson earns from the show.Whilst the TV star has worked hard to try and make sure the Diddl

261. New 'must-watch' Netflix series has fans demanding season two already after tuning in for 13 million hours

  • 2 weeks ago schedule
  • unilad.com language

A new Netflix series set in an elite private school has captivated fans to the point that they're begging for a second season just days after its release. There's good TV, and then there's TV that ca

262. Special agent reveals shocking items found inside Diddy’s closet during raid

  • 2 weeks ago schedule
  • unilad.com language

Warning: This article contains allegations of sex trafficking and abuse which some readers may find distressing.A special agent has spoken in court about what was discovered inside the closet of Sean

263. People stunned after seeing what $2,500 'unbreakable man' bootcamp really is

  • 2 weeks ago schedule
  • unilad.com language

Footage from an experience designed to create 'the unbreakable man' showing a man 'overcoming his fear and asserting his power' has left social media users gobsmacked. A video from 'The Unbreakable M

264. Shocking simulation shows what happens to your body when you fast for 36 hours and the extreme impact

  • 2 weeks ago schedule
  • unilad.com language

A mind-boggling simulation showing the impact fasting for a long period has on the body is currently going viral; however, some health experts aren’t quite so convinced.People fast for a whole load

265. Private investigator reveals surprising household item can prove someone is cheating

  • 2 weeks ago schedule
  • unilad.com language

A private investigator has revealed how you could utilise a common electrical item to confirm your suspicions of whether or not your spouse is cheating on you - and it might surprise you.People commi

266. Urgent warning to billions of Gmail users over dangerous 'no-reply' attack

  • 2 weeks ago schedule
  • unilad.com language

A tech expert has broken down 'clues' within a sophisticated phishing email which has been sent to Gmail users from a 'valid, signed email'. Founder of Ethereum Name Service, Nick Johnson, took to Tw

267. Doctors say this one drink can lower your risk of developing cancer

  • 2 weeks ago schedule
  • unilad.com language

Amid rising cases in young people developing cancer, there's one drink that can lower your risk of developing the disease significantly, according to health experts.Cancer has been on the rise in you

268. NASA issues warning for major solar storm that has already caused radio blackouts on Earth

  • 2 weeks ago schedule
  • unilad.com language

Experts have warned of mass blackouts and potential further communication disruptions across the Earth as the most intense solar flare this year is poised to create a freak solar event.On May 14, NAS

269. Death row inmate makes chilling final request to victim's family after he set elderly woman on fire

  • 2 weeks ago schedule
  • unilad.com language

A death row inmate issued a chilling final request to his victim's family shortly before he was executed earlier this week (May 20).Matthew Lee Johnson was sentenced to death after he splashed 76-yea

270. Columbia University president savagely booed at graduation after caving to Donald Trump's demands

  • 2 weeks ago schedule
  • unilad.com language

Columbia University students made it clear how they feel about their acting president as they barely let her get a word in during a speech at the Ivy League school's graduation ceremony. Acting presi

271. Everything we know about drug ‘containing ground-up human bones’ after Brit arrested for 'smuggling £1.2million worth'

  • 2 weeks ago schedule
  • ladbible.com language

Here is everything we know about the deadly drug 'kush', which has led to British woman Charlotte May Lee being detained in Sri Lanka.Earlier today, it was revealed the 21-year-old former flight atte

272. Jay Slater sent friend photo of him 'armed with knives' just hours before death, inquest hears

  • 2 weeks ago schedule
  • ladbible.com language

As the inquest into Jay Slater's death takes place today (21 May), a friend of his has said the teen sent him a photo ‘armed with knives’ just before his death.The 19-year-old from Lancashire was

273. Trump's $175,000,000,000 ‘Golden Dome’ explained as China issues scathing warning to the US

  • 2 weeks ago schedule
  • unilad.com language

Donald Trump has announced a 'Golden Dome' missile defence program revealing who's set to be involved, an anticipated timeline, and why it's all necessary. On May 20, Trump outlined his ideas for a $

274. People question how Donald Trump 'aced his cognitive test' as 'childish' moment goes viral

  • 2 weeks ago schedule
  • ladbible.com language

In the latest round of Donald Trump trolling, people have poked fun at him for a particularly ‘childish’ moment.It comes as the man running the US, heading up the government, state and military a

275. Woman shares full journey of 36-hour fast to show results of body transformation

  • 2 weeks ago schedule
  • ladbible.com language

A woman has shared her body transformation results after fasting for 36 hours.Alla Driksne, a content creator and professional chef, had been fasting on and off for five years at the time of her 2020

Cookie Policy

We use cookies and similar technologies to help the site provide a better user experience. By using the website you agree to our Cookie Policy, Terms of Use and Privacy Policy.