Actor Uses Compromised Accounts, Customized Social Engineering to Target Transport and Logistics Firms with Malware
ID: 03eec74e-9384-578d-9ab9-c1965c3560ba
STIX ID: report--03eec74e-9384-578d-9ab9-c1965c3560ba
Feed Name: infostealers.com
Threat Score
Proofpoint observed a targeted campaign abusing compromised legitimate email accounts within ongoing threads to distribute multiple malware families (Lumma Stealer, StealC, NetSupport, DanaBot, Arechclient2) to North American transportation and logistics companies using .URL attachments, SMB-hosted executables, and a ClickFix Base64 PowerShell flow; the brief includes numerous SHA256 hashes and URLs as IOCs and assesses the activity as financially motivated cybercrime.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
