Google's Blog Software Hijacked by Scammers
Google's blogger.com is being hijacked to spread malware through fake blogs, a security vendor warns. — John E. Dunn, Techworld — Google's blogger.com is being hijacked to spread malware through fake blogs, a security vendor has warned.
Context & Ripple Effects
This warning lands three months after Techworld examined how Google handles hacked sites, a piece that framed the search giant's cleanup policies as the backstop for compromised web properties. The new report inverts that framing: this time the abused infrastructure is Google's own — blogger.com, where fake blogs are being used as malware delivery vehicles according to a security vendor.
First-order effects
- Visitors to blogger.com face fake blogs seeded with malware, meaning Google's user base absorbs the immediate infection risk while Google inherits an abuse-cleanup burden on its own hosting stack.
Second-order effects
- Security vendors gain a fresh category of flagged content — Google-hosted pages — pressuring Google to tighten automated screening of blog creation or risk its domain reputation being priced into filters and search rankings.
Third-order effects
- If trusted free-hosting platforms keep doubling as malware distribution networks, platform operators shift from passive hosts to active abuse-detection businesses, and the credibility of a domain name itself becomes part of a site's security posture.
The trend: Attackers are increasingly laundering malware through high-trust hosted platforms rather than their own domains, making abuse of legitimate services a core battleground between scammers and platform operators.