logo

Invoice Phishing Alert: TA866 Deploys WasabiSeed & Screenshotter Malware

ID: 1ae5a3bc-af64-5288-8e8f-7379dcaf7aef

STIX ID: report--1ae5a3bc-af64-5288-8e8f-7379dcaf7aef

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2024-01-20

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

TA866 has resurfaced with a large-scale invoice-themed phishing campaign targeting North America that uses PDF decoys with OneDrive links to initiate multi-step infection chains delivering WasabiSeed and Screenshotter and enabling follow-on payloads like Rhadamanthys and DarkGate via TA571-distributed spam; the report also highlights an evasion technique that exploits security-product caching by serving benign CTA URLs that are later altered to point to malicious pages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.