Google Drive is used to host a fake login page that harvests user credentials. The page is hosted by Google and protected by Google’s SSL certificate. The attack is reminiscent of a similar phishing campaign that popped up a year ago. Google has a built-in safety mechanism for its online document storage service, and scans files for malicious code. Attackers can get access to a user’s email, calendar, documents, analytics, and any other features they’ve signed up for Google Apps for Business.”]
Source: https://www.csoonline.com/article/2953190/google-drive-phishing-is-back-with-obfuscation.html

