Brexit Email Tricks Users Into Downloading Malware
ID: 475361b7-157c-549e-b033-aa64f556f649
STIX ID: report--475361b7-157c-549e-b033-aa64f556f649
Feed Name: WatchGuard Secplicity Blog
**Executive summary:** A targeted phishing campaign distributed a Word document (Brexit 15.11.2018.docx) that instructs users to enable macros and uses an externally referenced .dotm template hosted at 109.248.148.42 (Latvia) to retrieve an OLE macro downloader, evading detection by keeping malicious macros out of the original document; metadata links point to Grizli777 and possibly Fancy Bear, though the command-and-control server was offline during analysis so full validation was not possible.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
