Fake Fedex Express Shipment For Pickup in iso delivers nanocore using Sendgrid

The next in the overnight malware campaigns is a fake Fedex Express email delivering Nanore RAT via an img ( Iso) file. They use email addresses and subjects that will entice a user to read the email and open the attachment. A very high proportion are … Continue reading Fake Fedex Express Shipment For Pickup in iso delivers nanocore using Sendgrid

More Fake DHL invoices delivering Remcos RAT via office XML files

An old favourite lure with this email with the subject of “DHL Shipping of Original invoice B/L dated 26/10/2018” pretending to come from DHL EXPRESS – < noreply@dhl.com >  with a malicious word doc attachment  delivers Remcos… Continue reading More Fake DHL invoices delivering Remcos RAT via office XML files

Fake DHL READ : (DHL Express) -Delivery Address Confirmation delivers Remcos Rat

Yet another fake or spoofed DHL delivery notification delivering what today turns out to be Remcos RAT . An email with the subject of “READ : (DHL Express) -Delivery Address Confirmation” Pretending to come  from dhlSender@dhl.com <nore… Continue reading Fake DHL READ : (DHL Express) -Delivery Address Confirmation delivers Remcos Rat

Lokibot campaign 17 September 2018

We are starting this Monday Morning with a Lokibot campaign being delivered via malicious word  docs, actually RTF files using CVE-2017-11882 Microsoft equation editor exploits.  I am seeing various email subjects. I have received 2 of each version so … Continue reading Lokibot campaign 17 September 2018

Fake DHL delivery notification Agent Tesla Keylogger

Yet another fake or spoofed DHL delivery notification delivering what looks like Agent Tesla keylogger. An email with the subject of “Vessel Schedule ETD:AUG 26 ,ETA:SEP 20” coming from  Donald Townsend <comercial@twistermedical.com&#62… Continue reading Fake DHL delivery notification Agent Tesla Keylogger

Fake DHL Arrival Notice or Shipment Notice delivers malware via embedded exe files inside MP3 music files

  Following on from last week with an almost identical DHL malware campaign, today I am seeing yet another email pretending to be a DHL Shipment Notification  with the subject of  Arrival Notice For BL – 06/08/2018 / Vessel – DHL ATLAN… Continue reading Fake DHL Arrival Notice or Shipment Notice delivers malware via embedded exe files inside MP3 music files