logo

LinkedIn information used to spread banking malware in the Netherlands

ID: 818b5051-278f-5ef8-bee0-48889518f05c

STIX ID: report--818b5051-278f-5ef8-bee0-48889518f05c

Feed Name: Fox-IT blog

Threat Score
70/100

Date Published: 2016-06-07

Date Updated: 2026-04-27

...
...

Fox-IT detected a Dutch-language, targeted phishing campaign delivering macro-enabled Word documents named with recipient-specific details; the macro fetches a binary (ledpronto.com/app/office.bin, sha256:c1e21a06a1fa1de2998392668b6910ca2be0d5d9ecc39bd3e3a2a3ae7623400d) identified as the Zeus Panda banking trojan that communicates with a C2 at skorianial.com (107.171.187.182). Recipients are social-engineered via LinkedIn-derived personal details and advised to scan systems if the attachment was opened and macros enabled.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.