logo

Ongoing Campaign Bombards Enterprises with Spam Emails and Phone Calls

ID: e64962c0-6658-5aa5-827a-ae91f3ceffb0

STIX ID: report--e64962c0-6658-5aa5-827a-ae91f3ceffb0

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2024-05-14

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Researchers observed an ongoing social-engineering campaign (since April 2024) that overwhelms enterprise inboxes with legitimate-looking subscription emails, then uses phone calls to coerce victims into installing remote-access tools (AnyDesk/Quick Assist) to enable follow-on credential theft, persistence (OpenSSH reverse shell), and lateral movement (attempted Cobalt Strike deployment). Concurrently, Phorpiex/Trik has been used to massively distribute LockBit Black ransomware via email, and Mallox actors are brute-forcing MSSQL servers to deploy Mallox ransomware via a .NET loader (PureCrypter); the activity ties into known criminal groups (FIN7, Black Basta) and demonstrates large-scale, active malicious operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.