Phishing emails were reported with attached malicious archives, which extracted a malicious document, and lead to suspected Dridex banking Trojan. The campaign uses various email subjects.
Another HR themed campaign was reported in which scammers masqueraded as a financial services company’s human resources. The campaign was reported as a potential phishing attack against the prospective employees, which could have been aimed at stealing or compromising the applicants’ PII for identity theft purposes. The scammers also used this phone number. “702-674-2348”
Another phishing email with the subject “Swift Euro 72K” was reported that contains an Excel attachment leading to malware.
A phishing email with the subject “invoice 0021019 from Citalia LLC” was reported recently. The campaign drops the Nanocore RAT on target machines.
A JP Morgan Chase themed phishing email with the subject “May 28, 2019 [msg-ID 36krn3]” was detected. The email contains an embedded URL that leads to a JP Morgan Chase credential harvesting page.
Unauthorized Remote Access
Indicators of Compromise
Swift Euro 72K
invoice 0021019 from Citalia LLC
May 28, 2019 [msg-ID 36krn3]
Block the threat indicators at their respective controls.
Closely monitor emails coming from untrusted sources.
Scan for these email subjects and block if found.
Do not click on URLs and do not download attachments received in untrusted emails.