<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Google表單 &#8211; 科技島-掌握科技新聞、科技職場最新資訊</title>
	<atom:link href="https://www.technice.com.tw/tag/google%e8%a1%a8%e5%96%ae/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.technice.com.tw</link>
	<description>專注於科技新聞、科技職場、科技知識相關資訊，包含生成式AI、人工智慧、Web 3.0、區塊鏈、科技職缺百科、生物科技、軟體發展、雲端技術等豐富內容，適合熱衷科技及從事科技專業人事第一手資訊的平台。</description>
	<lastBuildDate>Wed, 30 Jul 2025 03:44:15 +0000</lastBuildDate>
	<language>zh-TW</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.4.2</generator>

<image>
	<url>https://www.technice.com.tw/wp-content/uploads/2022/12/cropped-wordpress_512x512-150x150.png</url>
	<title>Google表單 &#8211; 科技島-掌握科技新聞、科技職場最新資訊</title>
	<link>https://www.technice.com.tw</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>加密貨幣新詐騙手法「Google表單」曝光 沒送出資料也能騙取個資</title>
		<link>https://www.technice.com.tw/techmanage/infosecurity/184641/</link>
					<comments>https://www.technice.com.tw/techmanage/infosecurity/184641/#respond</comments>
		
		<dc:creator><![CDATA[孫敬]]></dc:creator>
		<pubDate>Mon, 28 Jul 2025 07:47:56 +0000</pubDate>
				<category><![CDATA[資安]]></category>
		<category><![CDATA[生活]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Google表單]]></category>
		<category><![CDATA[加密貨幣]]></category>
		<guid isPermaLink="false">https://www.technice.com.tw/?p=184641</guid>

					<description><![CDATA[<p><img width="1200" height="675" src="https://www.technice.com.tw/wp-content/uploads/2025/07/Google-Forms.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Google表單" decoding="async" srcset="https://www.technice.com.tw/wp-content/uploads/2025/07/Google-Forms.jpg 1200w, https://www.technice.com.tw/wp-content/uploads/2025/07/Google-Forms-300x169.jpg 300w, https://www.technice.com.tw/wp-content/uploads/2025/07/Google-Forms-1024x576.jpg 1024w, https://www.technice.com.tw/wp-content/uploads/2025/07/Google-Forms-768x432.jpg 768w, https://www.technice.com.tw/wp-content/uploads/2025/07/Google-Forms-390x220.jpg 390w" sizes="(max-width: 1200px) 100vw, 1200px" title="加密貨幣新詐騙手法「Google表單」曝光 沒送出資料也能騙取個資 1"></p>
<p>Google表單的加密貨幣詐騙手法，主要透過電子郵件，插入一個Google表單連結來繞過垃圾郵件偵測，一旦點開表單，受害者會看到一個偽裝成知名加密貨幣交易所的頁面。<content><span style="font-weight: 400;">記者孫敬／編譯</span></p>
<p><span style="font-weight: 400;">人們日常生活中常用的Google表單工具，竟淪加密貨幣網路釣魚（Phishing）活動的溫床！這起始於2024年末、2025年第二季盛行的詐騙手法，主要透過電子郵件，插入一個Google表單連結來繞過垃圾郵件偵測，一旦點開表單，受害者會看到一個偽裝成知名加密貨幣交易所的頁面，恭喜他們有一筆「待處理的1.275比特幣（BTC）獎勵」即將發放。</span></p>
<p><b>延伸閱讀：<a href="https://www.technice.com.tw/techmanage/infosecurity/184282/" target="_blank" rel="noopener">達賴喇嘛生日前夕爆資安危機！中國駭客組織鎖定藏人網站散播惡意軟體</a></b></p>
<p>[caption id="attachment_184654" align="aligncenter" width="1200"]<img class="wp-image-184654 size-full" src="https://www.technice.com.tw/wp-content/uploads/2025/07/Google-Forms.jpg" alt="" width="1200" height="675" /> Google表單容易騙過信箱的垃圾郵件審查機制。（圖／123RF）[/caption]</p>
<h2><b>偽裝領取BTC獎勵，利用Google表單躲過垃圾郵件偵測</b></h2>
<p><span style="font-weight: 400;">當用戶點擊了Google表單連結後，會被引導到看似真實的提款入口網站，並要求驗證錢包地址來支付一筆手續費。然而，一旦輸入資訊並支付，所提供的憑證會立即被傳送到隱藏在Cloudflare Workers後方的指揮與控制（C2）伺服器，款項則會被轉移至混幣器，以此抹去資金流向。</span></p>
<p><span style="font-weight: 400;">卡巴斯基（Kaspersky）分析師指出，他們在2025年7月初的消費者端點例行遙測審查中，觀察到Google表單的釣魚郵件激增了63%，並將此活動標記為今年最有效的低技術社交工程攻擊之一。它利用了Google表單本身的通知引擎，因為每一封誘騙郵件都源自Google自家的SMTP基礎設施，網域信譽檢查幾乎總是回報「乾淨」結果，使得惡意郵件能幾乎完美地送達收件人的收件匣。</span></p>
<h2><b>技術剖析與防禦建議，單一JavaScript重導頁面，用戶須提高警覺</b></h2>
<p><span style="font-weight: 400;">根據洩漏的惡意表單顯示，主要利用與Google Apps Script綁定的WebHook，在受害者點擊「提交」的瞬間，便會悄無聲息地將數據洩露，甚至無需等待表單完成填寫。該腳本還會注入一次性的JavaScript重導代碼，將用戶重新導向至一個偽造的網站（例如 </span><span style="font-weight: 400;">claim-btc-id[.]online</span><span style="font-weight: 400;">），該網站擁有精美的React前端和Python Flask API，負責將所有請求代理到攻擊者的C2伺服器。</span></p>
<p><span style="font-weight: 400;">為有效防禦這類攻擊，資安專家建議採取多層次的防禦措施：</span></p>
<ol>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">內容威脅解除和重建（Content-disarm rules）： 設定規則，隔離任何未明確列入白名單的Google表單郵件。</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">瀏覽器擴充功能： 部署能夠阻止向不熟悉的Worker網域發送出站請求的瀏覽器擴充功能。</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">資安意識宣導</span><b>：</b><span style="font-weight: 400;"> 最重要的是，持續向大眾重申一個不變的原則，免費的加密貨幣絕不會透過填寫表單來發放。</span></li>
</ol>
<p><span style="font-weight: 400;">資料來源<a href="https://cybersecuritynews.com/hackers-leverage-google-forms-surveys/" target="_blank" rel="noopener">：Cyber Security News</a></span></content></p>
<p>這篇文章 <a rel="nofollow" href="https://www.technice.com.tw/techmanage/infosecurity/184641/">加密貨幣新詐騙手法「Google表單」曝光 沒送出資料也能騙取個資</a> 最早出現於 <a rel="nofollow" href="https://www.technice.com.tw">科技島-掌握科技新聞、科技職場最新資訊</a>。</p>
]]></description>
		
					<wfw:commentRss>https://www.technice.com.tw/techmanage/infosecurity/184641/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
