Analysis of a Dridex Banking Trojan Phish
ID: d3ce3cc6-7aff-5931-af33-a5dfe92518ae
STIX ID: report--d3ce3cc6-7aff-5931-af33-a5dfe92518ae
Feed Name: WatchGuard Secplicity Blog
Threat Score
This report details phishing campaigns exploiting COVID‑19 relief themes to deliver the Dridex banking trojan via macro-enabled documents and credential-harvesting sites that spoof Microsoft login pages; the author demonstrates an active compromise where entered credentials were stored on an exposed attacker server and provides detection and prevention advice (email red flags, WMI/PowerShell monitoring, and WatchGuard products).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
