Don’t trust ‘secure mail’! malicious Files Impersonating Credit Card Companies Are Being Distributed
ID: f450ef62-a8b7-5af4-8bab-52b46e74e862
STIX ID: report--f450ef62-a8b7-5af4-8bab-52b46e74e862
Feed Name: ASEC
**Executive summary:** AhnLab observed a phishing campaign impersonating a Korean credit card company that delivers LNK files which invoke mshta to run obfuscated VBScript and fetch decoy documents and multi-stage malware; the payload adapts its execution based on whether Windows Defender is running, downloading and decrypting different components (pipe.zip => 1.log/1.ps1/2.log for backdoor/infosteal/keylogging, or user.txt/sys.log => sys.dll and additional droppers) to perform credential and cookie theft, keylogging, clipboard theft, remote command execution, and downloader activity; recommended mitigations include checking registries and deleting suspicious files in %TEMP% and %LOCALAPPDATA%.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
