More AgentTesla keylogger and Nanocore RAT in one bundle

We are seeing a continuation of even more AgentTesla malspam campaigns again this morning. However today’s is somewhat different to usual and also delivers a Nanocore RAT. Actually the Nanocore RAT  is downloading the AgentTesla keylogger. And af… Continue reading More AgentTesla keylogger and Nanocore RAT in one bundle

More AgentTesla keylogger as fileless malware.

We are seeing a continuation of the new style AgentTesla malspam campaign again this morning. This is still using a multistage downloader eventually resulting in the AgentTesla keylogger / infostealer being run on the victim’s computer as a filel… Continue reading More AgentTesla keylogger as fileless malware.

AgentTesla keylogger as fileless malware.

I am seeing a somewhat different to usual AgentTesla malspam campaign this morning. This is using a multistage downloader eventually resulting in the AgentTesla keylogger / infostealer being run on the victim’s computer as a fileless malware. It … Continue reading AgentTesla keylogger as fileless malware.

Remcos Rat via fake invoice using multiple delivery methods.

I have heard of the “Belt and Braces ” approach to delivering malware before, but this malware campaign delivering Remcos Rat is using  the belt and 2 pairs of braces to try make sure the malware gets delivered. The email is a fairly typica… Continue reading Remcos Rat via fake invoice using multiple delivery methods.

Bitcoin verify your Identity phishing scam hosted on Microsoft Azure hosting

I  am seeing a bitcoin phishing scam campaign this morning hosted on Microsoft Azure/windows.net. The emails pretend to come from your own email address and are addressed to the same email address. All hosting companies get abused and used for malware,… Continue reading Bitcoin verify your Identity phishing scam hosted on Microsoft Azure hosting

More compromised windstream email sending malspam with Orion keylogger

Following on from Last Friday, it is looking like Windstream, Zimbra & Synacor still have a problem with accounts being compromised and mass malspam being sent.  Generally speaking the majority of ISPs are pretty good with blocking outgoing spam &#… Continue reading More compromised windstream email sending malspam with Orion keylogger

voicemail phishing scam involving compromised OneDrive for business site

We see lots of phishing attempts for email credentials. This one is slightly different than many others and somewhat more  complicated. It pretends to be a message to download a voicemail. You can now submit suspicious sites, emails and files via our S… Continue reading voicemail phishing scam involving compromised OneDrive for business site