fake Xero accounting software invoice delivers Dridex banking Trojan

Continuing with the never ending series of malware downloaders is an email with the subject of Your Xero Invoice INV-0855485  coming from subscription.notifications@xeronet.org which uses compromised sharepoint aka onedrive for business accounts to deliver Dridex banking Trojan Note: this was forwarded to me by a contact this morning who received it yesterday. Continue reading →