Fake Your Virgin Media bill is ready malspam delivers Dridex banking Trojan

The next in the never ending series of Malware  downloaders is an email with the subject of  Your Virgin Media bill is ready pretending to come from Virgin Media <webteam@virginmediaconnections.com> which delivers Dridex banking trojan They use email addresses and subjects that will entice, scare or persuade the recipient to read the email Continue reading → Continue reading Fake Your Virgin Media bill is ready malspam delivers Dridex banking Trojan

Whats!App Subscription Expired – Phishing

We see lots of phishing attempts . This one is trying to get your credit card details. It pretends to be a warning that your WhatsApp subscription has expired. They use email addresses and subjects that will entice a user to read the email and open the attachment. Remember many Continue reading → Continue reading Whats!App Subscription Expired – Phishing

Locky delivered by fake Scanning message pretending to come from random names @tayloredgroup.co.uk.

The next in the never ending series of Locky downloaders is an email with the subject of  Scanning  pretending to come from random names @tayloredgroup.co.uk. They use email addresses and subjects that will entice a user to read the email and open the attachment. tayloredgroup.co.uk has not been hacked or had their Continue reading → Continue reading Locky delivered by fake Scanning message pretending to come from random names @tayloredgroup.co.uk.

Locky delivered by fake Scanning message pretending to come from random names @tayloredgroup.co.uk.

The next in the never ending series of Locky downloaders is an email with the subject of  Scanning  pretending to come from random names @tayloredgroup.co.uk. They use email addresses and subjects that will entice a user to read the email and open the attachment. tayloredgroup.co.uk has not been hacked or had their Continue reading → Continue reading Locky delivered by fake Scanning message pretending to come from random names @tayloredgroup.co.uk.

fake OnePosting Invoice Ready to View malspam delivers Dridex banking Trojan

The next in the never ending series of malware downloaders is an email with the subject of  OnePosting Invoice Ready to View pretending to come from SPECTUR LIMITED <members@onenewpost.com>. This eventually delivers Dridex banking Trojan. They use email addresses and subjects that will entice a user to read the email and open the Continue reading → Continue reading fake OnePosting Invoice Ready to View malspam delivers Dridex banking Trojan

Fake True Telecom Invoice for August 2017 delivers Globeimposter ransomware

The next in the never ending series of malware  downloaders is an email with the subject of  45653946 – True Telecom Invoice for August 2017 ( random numbers)   pretending to come from billing@true-telecom.com. This is coming via the Necurs botnet but instead of delivering Locky today, this 2nd malspam run is Continue reading → Continue reading Fake True Telecom Invoice for August 2017 delivers Globeimposter ransomware

Fake True Telecom Invoice for August 2017 delivers Globeimposter ransomware

The next in the never ending series of malware  downloaders is an email with the subject of  45653946 – True Telecom Invoice for August 2017 ( random numbers)   pretending to come from billing@true-telecom.com. This is coming via the Necurs botnet but instead of delivering Locky today, this 2nd malspam run is Continue reading → Continue reading Fake True Telecom Invoice for August 2017 delivers Globeimposter ransomware

More Fake NatWest Bank messages with a password protected word doc delivers trickbot

An email with the subject of Important : Incoming BACs Documents pretending to come from NatWest Bank but actually coming from a look-a-like domain Natwest <message@natwestbacs.co.uk>   or  Natwest <message@natwestbacs.com> with a password protected malicious word doc attachment  is today’s latest spoof of a well-known company, bank or public authority delivering Trickbot banking Trojan Continue reading → Continue reading More Fake NatWest Bank messages with a password protected word doc delivers trickbot

More Fake NatWest Bank messages with a password protected word doc delivers trickbot

An email with the subject of Important : Incoming BACs Documents pretending to come from NatWest Bank but actually coming from a look-a-like domain Natwest <message@natwestbacs.co.uk>   or  Natwest <message@natwestbacs.com> with a password protected malicious word doc attachment  is today’s latest spoof of a well-known company, bank or public authority delivering Trickbot banking Trojan Continue reading → Continue reading More Fake NatWest Bank messages with a password protected word doc delivers trickbot

Fake Invoice INV-000379 from Property Lagoon Limited for Gleneagles Equestrian Centre delivers Locky ransomware

The next in the never ending series of Locky downloaders is an email with the subject of   Invoice INV-000379 from Property Lagoon Limited for Gleneagles Equestrian Centre ( random numbers)  pretending to come from a random name that matches the name in the email body  but appearing to come from  messaging-service@post.xero.com Continue reading → Continue reading Fake Invoice INV-000379 from Property Lagoon Limited for Gleneagles Equestrian Centre delivers Locky ransomware