logo

Actor Uses Compromised Accounts, Customized Social Engineering to Target Transport and Logistics Firms with Malware

ID: 03eec74e-9384-578d-9ab9-c1965c3560ba

STIX ID: report--03eec74e-9384-578d-9ab9-c1965c3560ba

Feed Name: infostealers.com

Threat Score
68/100

Date Published: 2024-09-25

Date Updated: 2026-04-28

Author: Alon Gal

...
...

Proofpoint observed a targeted campaign abusing compromised legitimate email accounts within ongoing threads to distribute multiple malware families (Lumma Stealer, StealC, NetSupport, DanaBot, Arechclient2) to North American transportation and logistics companies using .URL attachments, SMB-hosted executables, and a ClickFix Base64 PowerShell flow; the brief includes numerous SHA256 hashes and URLs as IOCs and assesses the activity as financially motivated cybercrime.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.