Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

A while ago, Google showed messages at the top of Gmail for some users "We believe state-sponsored attackers might be attempting to compromise your account or computer".

If they had send some OAuth tokens for a honeypot gmail account to the C&C server used for these attacks, they could then track the usage patterns of that token, and find all the other attacked users. Perhaps thats how they identified who was being attacked?



I was thinking the exact same thing. It's possible that because it has been so long since Google identified this threat actor, they did in fact use a honeypot account to trace the attackers prior to burning them.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: