Skip to main content
  1. Home
  2. Computing
  3. News

Hackers found a way to access Gmail, Outlook, and Yahoo inboxes

Add as a preferred source on Google

Iranian state-sponsored hackers have discovered ways to infiltrate the Gmail, Yahoo, and Outlook inboxes of at least two dozen high-profile users and download their content, according to a report from the Google Threat Analysis Group (TAG).

The government-backed group known as Charming Kitten originally developed a hacking tool called Hyperscape in 2020 and has used it to orchestrate the recent cyberattacks. TAG was able to get a hold of a version of this tool for analysis, TechRadar reported.

NurPhoto/Getty Images

Google explained that the attack works in a stealth fashion where there is no typical hacking ritual, such as tricking a user into downloading malware. Instead, hackers control the tool from their end, taking advantage of vulnerabilities, such as compromised account credentials or stolen session cookies, in order to access an account.

Recommended Videos

While this particular cyberattack may have been politically motivated, Google is clearly interested in how these vulnerabilities might be used by others in the future.

A recent report from Sophos details how cookie stealing is among the latest trends in cybercrime. Hackers use the method to bypass security measures such as multifactor authentication and access private databases.

In this case, once logged into the email account, hackers use the tool to trick the email service into thinking a browser is outdated, which then switches it to a basic HTML view. Then it changes the inbox language to English and opens emails individually to begin downloading them in a .eml format. The hackers then mark any opened emails as unread and delete any warning emails, set the inbox back to its original language, and exit.

Despite its seemingly smooth execution, Google has learned a lot about the cyberattacks and has notified all of the known accounts that were affected through its Government Backed Attacker Warnings. TAG has deciphered that the tool was written in .NET for Windows PCs and noted attacks might work differently in Yahoo and Outlook inboxes. At this time, the security group has only tested the tool in Gmail.

Fionna Agomuoh
Fionna Agomuoh is a Computing Writer at Digital Trends. She covers a range of topics in the computing space, including…
Gemini Notebook’s latest update makes it a better study companion
Google is adding voice conversations, lecture recording, interactive quizzes, and short video overviews to its AI-powered notebook.
Gemini Notebook update for students

Google is giving Gemini Notebook, formerly NotebookLM, a major upgrade for students, adding new features designed to help them understand difficult concepts, capture lectures, and turn study materials into interactive learning tools. The update lands alongside a free year of Google's paid AI plan for eligible college students.

Gemini Notebook can now talk you through your notes

Read more
LG 39GX950B review: An ultrawide OLED that gets remarkably close to having it all
LG’s 39-inch 5K2K OLED combines high-end picture quality with seriously fast gaming
Electronics, Screen, Computer Hardware

see at bestbuy

Quick Verdict

Read more
Should we feel bad about deleting an AI? One expert says it’s time to find out
If AI can learn, remember, and make increasingly complex decisions, one expert thinks we should be more careful about how we say goodbye.
an on off toggle

Turning off an AI might sound as simple as hitting a switch, but according to futurist and University of Technology Sydney professor Rocky Scopelliti, that mindset needs to change fast. As first reported by TechXplore, Scopelliti's new book, The Conscious Code, Scopelliti argues that as AI systems get better at reflecting on their own choices, deleting them without a second thought could actually cause harm.

He's not asking us to hand robots legal rights. Instead, he wants us to accept what he calls a duty of good stewardship, basically treating AI responsibly because we're the ones holding the power, not because the AI is demanding it. As he puts it, our design choices can quietly cause damage by wiping out an AI's "learned moral dispositions" without warning.

Read more