Ongoing Campaign Bombards Enterprises with Spam Emails and Phone Calls
ID: e64962c0-6658-5aa5-827a-ae91f3ceffb0
STIX ID: report--e64962c0-6658-5aa5-827a-ae91f3ceffb0
Feed Name: The Hacker News
Researchers observed an ongoing social-engineering campaign (since April 2024) that overwhelms enterprise inboxes with legitimate-looking subscription emails, then uses phone calls to coerce victims into installing remote-access tools (AnyDesk/Quick Assist) to enable follow-on credential theft, persistence (OpenSSH reverse shell), and lateral movement (attempted Cobalt Strike deployment). Concurrently, Phorpiex/Trik has been used to massively distribute LockBit Black ransomware via email, and Mallox actors are brute-forcing MSSQL servers to deploy Mallox ransomware via a .NET loader (PureCrypter); the activity ties into known criminal groups (FIN7, Black Basta) and demonstrates large-scale, active malicious operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
