logo

Brexit Email Tricks Users Into Downloading Malware

ID: 475361b7-157c-549e-b033-aa64f556f649

STIX ID: report--475361b7-157c-549e-b033-aa64f556f649

Feed Name: WatchGuard Secplicity Blog

Threat Score
55/100

Date Published: 2018-12-04

Date Updated: 2026-05-01

Author: The Editor

...
...

**Executive summary:** A targeted phishing campaign distributed a Word document (Brexit 15.11.2018.docx) that instructs users to enable macros and uses an externally referenced .dotm template hosted at 109.248.148.42 (Latvia) to retrieve an OLE macro downloader, evading detection by keeping malicious macros out of the original document; metadata links point to Grizli777 and possibly Fancy Bear, though the command-and-control server was offline during analysis so full validation was not possible.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.