logo

Phishing targeting Polish SMBs continues via ModiLoader

ID: e55c2f97-e384-5988-8601-d75b914aec69

STIX ID: report--e55c2f97-e384-5988-8601-d75b914aec69

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
70/100

Date Published: 2024-07-30

Date Updated: 2026-05-01

...
...

ESET detected nine ModiLoader-based phishing campaigns in May 2024 targeting SMBs (primarily in Poland) that used spearphishing attachments (ISO/RAR with obfuscated scripts) to deploy ModiLoader, which retrieved Agent Tesla, Formbook, or Rescoms; attackers relied on compromised email accounts and servers and hosted payloads on OneDrive or hacked infrastructure, and the report includes IoCs and MITRE ATT&CK mappings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.