logo

Transportation Companies Hit by Cyberattacks Using Lumma Stealer and NetSupport Malware

ID: 82824caf-c40d-53f0-961b-d6932f021113

STIX ID: report--82824caf-c40d-53f0-961b-d6932f021113

Feed Name: Proofpoint Blog

Threat Score
75/100

Date Published: 2024-09-25

Date Updated: 2026-04-28

...
...

Proofpoint reported a targeted phishing campaign (May–Aug 2024) against North American transportation and logistics firms that leverages compromised corporate email accounts to inject malicious content into legitimate threads and deliver a range of information stealers and RATs. The actors used .URL attachments and Google Drive links that fetch payloads over SMB, and later adopted a ClickFix-style Base64 PowerShell prompt to deploy DanaBot and other malware, indicating researched, sector-specific social engineering and evolving infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.