Phishing targeting Polish SMBs continues via ModiLoader
ID: e55c2f97-e384-5988-8601-d75b914aec69
STIX ID: report--e55c2f97-e384-5988-8601-d75b914aec69
Feed Name: WeLiveSecurity (ESET Research)
Threat Score
ESET detected nine ModiLoader-based phishing campaigns in May 2024 targeting SMBs (primarily in Poland) that used spearphishing attachments (ISO/RAR with obfuscated scripts) to deploy ModiLoader, which retrieved Agent Tesla, Formbook, or Rescoms; attackers relied on compromised email accounts and servers and hosted payloads on OneDrive or hacked infrastructure, and the report includes IoCs and MITRE ATT&CK mappings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
