Spam campaign: Netwire RAT via paste.ee and MS Excel to German users

struppigel

Moderator
Thread author
Verified
Staff Member
Well-known
Apr 9, 2020
656
My writeup of a Netwire spam campaign targeting Germany yesterday.


At noon on 13. April 2020 our monitoring system created an alert because DeepRay reported more hits than usual for one particular detection on PowerShell downloaders. The alarm system is there to see early if something goes wrong. However, this alarm went off because of a spam campaign hitting our German customers. The detections were all legitimately preventing the malware downloader from doing it's job.

We investigated the threat and also found BEAST-related entries which showed that the culprit were Excel documents delivered by email. While we do not receive the Excel or email documents themselves, we do see infection chains reported by BEAST for those customers that agreed to the Malware Information Initiative (Mii).

...
 

struppigel

Moderator
Thread author
Verified
Staff Member
Well-known
Apr 9, 2020
656
Confirmed related @upnorth
Unbenannt.png
Unbenannt2.png
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top