Invoice Phishing Alert: TA866 Deploys WasabiSeed & Screenshotter Malware
ID: 1ae5a3bc-af64-5288-8e8f-7379dcaf7aef
STIX ID: report--1ae5a3bc-af64-5288-8e8f-7379dcaf7aef
Feed Name: The Hacker News
Threat Score
TA866 has resurfaced with a large-scale invoice-themed phishing campaign targeting North America that uses PDF decoys with OneDrive links to initiate multi-step infection chains delivering WasabiSeed and Screenshotter and enabling follow-on payloads like Rhadamanthys and DarkGate via TA571-distributed spam; the report also highlights an evasion technique that exploits security-product caching by serving benign CTA URLs that are later altered to point to malicious pages.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
