{"id":426577,"date":"2026-10-11T07:04:26","date_gmt":"2026-10-11T07:04:26","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=426577"},"modified":"2026-10-11T07:04:26","modified_gmt":"2026-10-11T07:04:26","slug":"pec-invoice-zip-mintsloader-malware-scam","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/pec-invoice-zip-mintsloader-malware-scam\/","title":{"rendered":"PEC Invoice Scam: The Overdue Payment ZIP That Installs MintsLoader Malware"},"content":{"rendered":"<p>A certified email says an invoice is overdue. The subject sounds urgent, the sender looks like a business, and a ZIP attachment supposedly holds the paperwork.<\/p><div id=\"mwtad83914452\" class=\"gas_fallback-ad_309684--placement_406659\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>Before opening it to find out what you owe, check how this PEC invoice scam turns an ordinary accounting task into something much more serious.<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1536\" height=\"1024\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/pec-invoice-zip-mintsloader-malware-scam-illustration.png\" class=\"wp-image-426578\" alt=\"Illustrative PEC invoice email with a payment reminder and ZIP attachment\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/pec-invoice-zip-mintsloader-malware-scam-illustration.png 1536w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/pec-invoice-zip-mintsloader-malware-scam-illustration-300x200.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/pec-invoice-zip-mintsloader-malware-scam-illustration-1024x683.png 1024w\" sizes=\"auto, (max-width: 1536px) 100vw, 1536px\" \/><\/figure>\n<div id=\"mwtad27804386\" class=\"gas_fallback-ad_309746-ad_309685-placement_406660\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<h3>A payment reminder sent through a trusted channel<\/h3>\n<p>PEC is Italy&#8217;s certified email system. Businesses use it for important correspondence, which gives an unexpected invoice reminder more weight than ordinary junk mail.<\/p><div id=\"mwtad3219548599\" class=\"gas_fallback-ad_381396-ad_309685-placement_406667\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>In this campaign, criminals abuse real, compromised PEC accounts. The message isn&#8217;t made trustworthy simply because it traveled through a genuine certified mailbox.<\/p>\n<p>The <a href=\"https:\/\/cert-agid.gov.it\/news\/mintsloader-via-pec-falsi-solleciti-di-pagamento-per-diffondere-malware\/\" target=\"_blank\" rel=\"noopener\">Italian government&#8217;s CERT-AGID warning<\/a> identifies false unpaid-invoice demands with malicious ZIP attachments. This is a documented malware campaign, not an unresolved billing complaint.<\/p>\n<p>You may recognize the language of a supplier chasing payment. That familiarity is the lure: opening the attached documentation feels like the responsible thing to do.<\/p><div id=\"mwtad2787537345\" class=\"gas_fallback-ad_309686-ad_309685-placement_406668\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The lead image illustrates that kind of inbox message. It isn&#8217;t a copy of a victim&#8217;s correspondence, and its addresses are fictional.<\/p>\n<h3>The attachment is not the invoice you expect<\/h3>\n<p>The ZIP contains an HTML file rather than the expected invoice. That file starts a download chain involving JavaScript, Windows components, PowerShell, and MintsLoader.<\/p>\n<p>MintsLoader is used to fetch and start further malicious software. The eventual risk can include remote access or information theft, depending on what follows.<\/p><div id=\"mwtad1176163275\" class=\"gas_fallback-ad_381401-ad_309685-placement_406669\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>For the reader, the important difference is simple. You&#8217;re being asked to open paperwork, but the attachment leads toward running software on your computer.<\/p>\n<p>Receiving the message isn&#8217;t the same as executing that chain. What you opened, downloaded, or ran determines the response you need.<\/p>\n<h3>The details worth checking before touching the ZIP<\/h3>\n<ul>\n<li>An unexpected demand refers to overdue payment or an irregular accounting position.<\/li>\n<li>The attachment is an archive, even though you&#8217;re expecting a readable invoice.<\/li>\n<li>A familiar-looking sender is being used to make the request feel official.<\/li>\n<li>The message encourages a quick response before you confirm the underlying bill.<\/li>\n<li>The contents lead away from ordinary paperwork toward scripts or software execution.<\/li>\n<\/ul>\n<div id=\"mwtad1130644493\" class=\"gas_fallback-ad_381404-ad_309685-placement_406670\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>Those clues are useful together. A ZIP can have legitimate uses, but an unexpected invoice archive needs independent verification before anyone opens its contents.<\/p>\n<p>The safe check happens outside the message. Ask your accounting team or known supplier contact whether the invoice exists and how its documents should arrive.<\/p>\n<div id=\"mwtad2832275358\" class=\"gas_fallback-ad_309747-ad_309685-placement_406661\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Why Certified Email Can Still Carry a Dangerous Attachment<\/h2>\n<p>It&#8217;s understandable to trust PEC more than a random email. The problem starts when trust in the delivery system becomes trust in everything inside the envelope.<\/p>\n<p>Certification concerns the transmission and delivery process. It doesn&#8217;t guarantee that the sender&#8217;s account remains under its owner&#8217;s control or that a file is harmless.<\/p>\n<p>A compromised mailbox can send a message that looks like normal correspondence from that account. The business whose identity appears may also be a victim.<\/p>\n<p>The address can be real while the document is dangerous. Ask the supplier whether they sent this particular invoice, not just whether the mailbox belongs to them.<\/p>\n<p>If you already work with the apparent sender, use a contact from your existing records. Don&#8217;t treat a new number inside the demand as independent confirmation.<\/p>\n<p>Look at the commercial context, too. Does the invoice match a purchase order, an agreed service, and the normal billing schedule?<\/p>\n<p>Even a recognizable amount needs checking. It may resemble a routine expense without corresponding to a bill your organization actually approved.<\/p>\n<p>For a small business, the person reading PEC may also handle payments. Separating document review from payment approval helps prevent one hurried decision from doing both.<\/p>\n<p>Keep genuine obligations separate from this suspicious attachment. If a real invoice is overdue, settle it through the supplier&#8217;s verified process, not through untrusted files.<\/p>\n<div id=\"mwtad161604427\" class=\"gas_fallback-ad_309748-ad_309685-placement_406662\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the PEC Invoice Scam Works<\/h2>\n<h3>Step 1: The message creates an urgent accounting problem<\/h3>\n<p>The email begins with an unpaid-invoice claim. It may describe a pending payment, an expired invoice, or an accounting position that needs immediate attention.<\/p>\n<p>The wording pushes a practical worry rather than an extravagant prize. A recipient wants to avoid late fees, interrupted service, or embarrassment with a supplier.<\/p>\n<p>That makes the request easy to pass along internally. Someone may forward it to accounting without first asking whether the sender authorized it.<\/p>\n<p>If you forward it for investigation, identify it as suspicious. Otherwise, the next person can mistake your forwarding message for approval to open the archive.<\/p>\n<h3>Step 2: The ZIP makes the dangerous content look like documentation<\/h3>\n<p>The attachment&#8217;s name suggests an invoice or an administrative document. The archive itself doesn&#8217;t reveal the full risk until its contents are examined safely.<\/p>\n<p>A reader may assume the sender compressed several pages together. That assumption gives the inner file an opportunity to be opened without much thought.<\/p>\n<p>Don&#8217;t rely on the familiar beginning of a filename. The actual file type matters, especially when an invoice turns out to be HTML rather than expected paperwork.<\/p>\n<p>You don&#8217;t need to extract it to investigate the bill. Request confirmation and a safe replacement through the contact you already know.<\/p>\n<h3>Step 3: The HTML file reaches out for another component<\/h3>\n<p>HTML normally belongs to web content. In the identified attack, opening the inner HTML contacts attacker infrastructure and retrieves a JavaScript file.<\/p>\n<p>At this point, the document is no longer simply showing an invoice. It is bringing another file into a process the recipient didn&#8217;t intend to start.<\/p>\n<p>An unfamiliar download after opening supposed paperwork is a reason to stop. Don&#8217;t open the new file because the invoice hasn&#8217;t appeared yet.<\/p>\n<p>Record what happened and tell your IT contact. Avoid reopening the HTML to see whether the second attempt produces a more useful result.<\/p>\n<h3>Step 4: Windows scripting components continue the infection<\/h3>\n<p>The documented chain uses components already present in Windows, followed by stages involving PowerShell. Familiar software names therefore don&#8217;t make the activity benign.<\/p>\n<p>The danger is what those components are instructed to do. A legitimate scripting tool can also be used to start an attack.<\/p>\n<p>This isn&#8217;t a request to repair your computer or update invoice-reading software. Don&#8217;t follow additional instructions that demand execution, security exceptions, or disabled protections.<\/p>\n<p>If you ran anything, explain that clearly when seeking help. Saying only \u201cI opened an email\u201d can hide the part that requires a device investigation.<\/p>\n<h3>Step 5: MintsLoader opens the door to further malware<\/h3>\n<p>The loader can obtain additional malware after the initial attachment stage. That is why deleting the original email doesn&#8217;t resolve a computer that has been compromised.<\/p>\n<p>The first file may only be the beginning. A responder needs to check the device and any accounts used during the possible compromise.<\/p>\n<p>Don&#8217;t assume a specific stealer or remote-access program infected every recipient. The campaign establishes the loader chain, not an identical outcome on every machine.<\/p>\n<p>Take the exposure seriously without guessing. Isolation, professional assessment, and account protection from a clean device give you a useful starting point.<\/p>\n<div id=\"mwtad544732553\" class=\"gas_fallback-ad_318930-ad_309685-placement_406663\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3818335085\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>A Blank Page Doesn&#8217;t Make the Attachment Safe<\/h2>\n<p>Sometimes the expected invoice never appears. A reader sees an error, an empty window, or a failed download and assumes the attachment simply doesn&#8217;t work.<\/p>\n<p>That isn&#8217;t a reliable safety test. CERT-AGID found infrastructure in this campaign that was initially inactive and became operational later.<\/p>\n<p>Repeatedly opening a suspicious attachment can therefore create another opportunity for the attack. A failed first attempt isn&#8217;t an invitation to try again.<\/p>\n<p>Don&#8217;t switch browsers, turn off filtering, or use another computer merely to make the invoice open. You&#8217;re moving the unverified file to another environment.<\/p>\n<p>Instead, write down whether anything downloaded and whether you launched it. Those details are more useful than reproducing the behavior for yourself.<\/p>\n<p>An error also doesn&#8217;t prove that malware ran. Keep the distinction: uncertainty calls for an exposure check, not a confident claim that every device is infected.<\/p>\n<h2>Checking the Invoice Without Following the Attacker&#8217;s Instructions<\/h2>\n<p>Start with your own records. Match the alleged supplier, invoice number, and service against documents that existed before this email arrived.<\/p>\n<p>If you can&#8217;t find a match, ask the business through its established contact. A reply to the same compromised mailbox may go straight back to the attacker.<\/p>\n<p>When you speak to a known contact, describe the subject and attachment type without sending them an executable file to open.<\/p>\n<p>Ask whether they sent the notice, whether that invoice is outstanding, and whether they can provide the document through their ordinary secure channel.<\/p>\n<p>For employees, follow the organization&#8217;s suspicious-email process. An IT team can preserve the message and inspect it without putting another employee&#8217;s computer at risk.<\/p>\n<p>Keep original headers and delivery information where possible. Screenshots help explain the lure, but the original message can contain useful technical evidence.<\/p>\n<p>Don&#8217;t upload company invoices or suspicious attachments to random online tools. They can include confidential financial information, customer details, or dangerous content.<\/p>\n<p>Once the sender confirms a compromise, other recipients may need warning. Coordinate that with the mailbox owner and your IT team rather than forwarding the live attachment.<\/p>\n<h2>What to Do if You Have Fallen Victim to This Scam<\/h2>\n<ol>\n<li>\n<p><strong>Stop using the attachment.<\/strong> Close its window and don&#8217;t run any associated download. Note whether you extracted the ZIP, opened HTML, or launched a script.<\/p>\n<p>If the email is all you saw, report it through your mailbox&#8217;s security process. You don&#8217;t need to wipe a computer merely for receiving it.<\/p>\n<\/li>\n<li>\n<p><strong>Contain a possible execution.<\/strong> If you ran a file or noticed unexpected software activity, disconnect the affected computer from network connections and notify IT immediately.<\/p>\n<p>Use a different, trusted device for urgent communications. Avoid banking, password changes, and sensitive company logins on the machine being investigated.<\/p>\n<\/li>\n<li>\n<p><strong>Keep evidence for the responder.<\/strong> Preserve the email, sender address, attachment name, arrival time, and any visible warnings. Don&#8217;t reopen a file to obtain a better screenshot.<\/p>\n<p>Give your IT team the original message using its approved method. Explain any security prompt you accepted and any program you remember launching.<\/p>\n<\/li>\n<li>\n<p><strong>Check and clean the device.<\/strong> Follow your IT team&#8217;s instructions. On a personal Windows computer, update protection tools and investigate downloads before resuming sensitive work.<\/p>\n<p><a href=\"https:\/\/malwaretips.com\/get\/malwarebytes-free\" target=\"_blank\" rel=\"noopener sponsored\" data-google-vignette=\"false\">Malwarebytes<\/a> can help check for malicious software. Its scan is a cleanup aid, not proof that accounts or payments are now safe.<\/p>\n<p><a href=\"https:\/\/support.microsoft.com\/en-us\/windows\/security\/threat-malware-protection\/virus-and-threat-protection-in-the-windows-security-app\" target=\"_blank\" rel=\"noopener\">Microsoft&#8217;s Windows Security guidance<\/a> explains available scans, including offline scanning. A serious compromise may require rebuilding the system rather than trusting one clean result.<\/p>\n<\/li>\n<li>\n<p><strong>Secure accounts from an unaffected device.<\/strong> Start with your email and important work accounts. Change exposed passwords, review sessions, and enable appropriate multifactor protection.<\/p>\n<p>If the computer stored business or banking credentials, tell the relevant administrators or bank what happened. They can help decide what access should be revoked.<\/p>\n<\/li>\n<li>\n<p><strong>Address any payment separately.<\/strong> If you sent money after the demand, contact your bank promptly with the recipient, amount, time, and invoice claim.<\/p>\n<p>Ask whether the transfer can be stopped or investigated. Malware removal alone won&#8217;t retrieve a payment, and no outcome should be promised before the bank reviews it.<\/p>\n<\/li>\n<li>\n<p><strong>Report and reduce repeat exposure.<\/strong> Notify the impersonated supplier and your PEC provider through trusted contacts. Share safe warning details with colleagues who may receive similar demands.<\/p>\n<p>For future browsing, <a href=\"https:\/\/malwaretips.com\/get\/adguard\" target=\"_blank\" rel=\"noopener sponsored\" data-google-vignette=\"false\">AdGuard<\/a> can add filtering against some risky destinations. It doesn&#8217;t authenticate invoices or make running a suspicious attachment safe.<\/p>\n<\/li>\n<\/ol>\n<h2>Helping an Accounting Team Avoid the Same Trap<\/h2>\n<p>A useful rule is more specific than \u201cbe careful with email.\u201d Unexpected invoice archives should be verified with the supplier before their contents are opened.<\/p>\n<p>Give staff an easy route for that check. If reporting an attachment takes longer than paying a routine bill, hurried employees may choose the wrong shortcut.<\/p>\n<p>Keep supplier contacts in an established system. Contact information copied from a new payment demand shouldn&#8217;t silently replace the details already on file.<\/p>\n<p>For shared inboxes, record who investigated a notice and what was confirmed. Otherwise, one person may clear the message while another opens its archive later.<\/p>\n<p>Make it safe to report a mistake quickly. An employee who fears blame may delay mentioning that they ran the downloaded file.<\/p>\n<p>The best response isn&#8217;t an interrogation about why they clicked. Ask what opened, when it happened, and which accounts were used afterward.<\/p>\n<p>If suspicious PEC mail came from your own account, involve your provider and IT team. Protect the mailbox and warn contacts without assuming every outgoing message was legitimate.<\/p>\n<p>Review any recent payment-detail changes associated with that account. An attachment campaign and a fraudulent payment request require separate checks, even if they appear in one conversation.<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<h3>Is every PEC invoice email a scam?<\/h3>\n<p>No. PEC is a legitimate system. This warning concerns a confirmed campaign using compromised mailboxes and dangerous attachments, not ordinary certified business correspondence.<\/p>\n<h3>Does a real sender address prove the attachment is safe?<\/h3>\n<p>No. An account can be compromised. Confirm the actual invoice with an established contact before trusting an unexpected archive, even when the address looks familiar.<\/p>\n<h3>Did I get infected just by receiving the email?<\/h3>\n<p>Receiving it doesn&#8217;t establish infection. The important details are whether you opened the inner file, downloaded another component, or ran software associated with it.<\/p>\n<h3>Why is an HTML file inside an invoice ZIP suspicious?<\/h3>\n<p>In this attack, HTML initiates another download instead of providing the expected invoice. Stop and verify the document rather than launching anything that arrives afterward.<\/p>\n<h3>Can I retry if the invoice page was blank?<\/h3>\n<p>Don&#8217;t retry a suspicious attachment. Infrastructure may change. Ask the sender for independently verified documentation and let a qualified responder assess any possible execution.<\/p>\n<h3>Will deleting the email remove MintsLoader?<\/h3>\n<p>Deleting a message doesn&#8217;t remove malware already running on a computer. Investigate the device and protect exposed accounts before returning to sensitive activity.<\/p>\n<h2>The Bottom Line<\/h2>\n<p>Don&#8217;t open an unexpected PEC invoice ZIP to settle an unverified debt. This documented campaign replaces ordinary paperwork with a malware-delivery chain.<\/p>\n<p>Confirm the bill through an existing supplier contact. If you already ran a file, isolate the computer and get security help before using it again.<\/p>\n<p>If money or credentials were also shared, contact the bank or account administrator from a clean device. Treat payment recovery and device cleanup as separate urgent tasks.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A certified email says an invoice is overdue. The subject sounds urgent, the sender looks like a business, and a ZIP attachment supposedly holds the paperwork. Before opening it to find out what you owe, &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"PEC Invoice Scam: The Overdue Payment ZIP That Installs MintsLoader Malware\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/pec-invoice-zip-mintsloader-malware-scam\/#more-426577\" aria-label=\"Read more about PEC Invoice Scam: The Overdue Payment ZIP That Installs MintsLoader Malware\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":426578,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[],"class_list":["post-426577","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/426577","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=426577"}],"version-history":[{"count":3,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/426577\/revisions"}],"predecessor-version":[{"id":426726,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/426577\/revisions\/426726"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/426578"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=426577"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=426577"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=426577"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}