Phishing alert: This fake email about a bank payment delivers malware

silversurfer

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,131
Researchers at Fortinet have uncovered a new Remcos RAT campaign – with the new variant titled "2.5.0 Pro" according to hard coded strings in the malicious code which was compiled in September – indicating the freshness of this variant.
These attacks begin with an attempt to trick the victim into opening a malicious ZIP file under the pretence of payments being made into a bank account. The phishing email users spoofing to make it look as if it comes from a valid domain.
The .ZIP file is a gateway to a .TXT extension which runs a PowerShell script when activated, executing the installation of the malware onto the victim's Windows machine.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top