Locky delivered by fake Scanning message pretending to come from random names @tayloredgroup.co.uk.

The next in the never ending series of Locky downloaders is an email with the subject of  Scanning  pretending to come from random names @tayloredgroup.co.uk. They use email addresses and subjects that will entice a user to read the email and open the attachment. tayloredgroup.co.uk has not been hacked or had their Continue reading → Continue reading Locky delivered by fake Scanning message pretending to come from random names @tayloredgroup.co.uk.

Locky delivered by fake Scanning message pretending to come from random names @tayloredgroup.co.uk.

The next in the never ending series of Locky downloaders is an email with the subject of  Scanning  pretending to come from random names @tayloredgroup.co.uk. They use email addresses and subjects that will entice a user to read the email and open the attachment. tayloredgroup.co.uk has not been hacked or had their Continue reading → Continue reading Locky delivered by fake Scanning message pretending to come from random names @tayloredgroup.co.uk.

fake OnePosting Invoice Ready to View malspam delivers Dridex banking Trojan

The next in the never ending series of malware downloaders is an email with the subject of  OnePosting Invoice Ready to View pretending to come from SPECTUR LIMITED <members@onenewpost.com>. This eventually delivers Dridex banking Trojan. They use email addresses and subjects that will entice a user to read the email and open the Continue reading → Continue reading fake OnePosting Invoice Ready to View malspam delivers Dridex banking Trojan

Fake True Telecom Invoice for August 2017 delivers Globeimposter ransomware

The next in the never ending series of malware  downloaders is an email with the subject of  45653946 – True Telecom Invoice for August 2017 ( random numbers)   pretending to come from billing@true-telecom.com. This is coming via the Necurs botnet but instead of delivering Locky today, this 2nd malspam run is Continue reading → Continue reading Fake True Telecom Invoice for August 2017 delivers Globeimposter ransomware

Fake True Telecom Invoice for August 2017 delivers Globeimposter ransomware

The next in the never ending series of malware  downloaders is an email with the subject of  45653946 – True Telecom Invoice for August 2017 ( random numbers)   pretending to come from billing@true-telecom.com. This is coming via the Necurs botnet but instead of delivering Locky today, this 2nd malspam run is Continue reading → Continue reading Fake True Telecom Invoice for August 2017 delivers Globeimposter ransomware

Fake Invoice INV-000379 from Property Lagoon Limited for Gleneagles Equestrian Centre delivers Locky ransomware

The next in the never ending series of Locky downloaders is an email with the subject of   Invoice INV-000379 from Property Lagoon Limited for Gleneagles Equestrian Centre ( random numbers)  pretending to come from a random name that matches the name in the email body  but appearing to come from  messaging-service@post.xero.com Continue reading → Continue reading Fake Invoice INV-000379 from Property Lagoon Limited for Gleneagles Equestrian Centre delivers Locky ransomware

Fake Dropbox Please verify your email address delivers Locky ransomware

We are seeing a run of a very different Locky delivery email tonight. This only seems to work properly in Google Chrome, Firefox gives a simple download file box and  Internet Explorer gives error messages on clicking the  “click here” link. This means that Internet Explorer users will be safe Continue reading → Continue reading Fake Dropbox Please verify your email address delivers Locky ransomware

Fake “Your latest BT OneBill is available now” malspam leads to Dridex banking trojan

An email with the subject of Your latest BT OneBill is available now  pretending to come from BT  but actually coming from a different domain ebilling4business@btdnet.com   that can just about be mistaken for  a genuine BT email address is today’s latest spoof of a well-known company, bank or public authority delivering Dridex banking Trojan Continue reading → Continue reading Fake “Your latest BT OneBill is available now” malspam leads to Dridex banking trojan

Fake “Your latest BT OneBill is available now” malspam leads to Dridex banking trojan

An email with the subject of Your latest BT OneBill is available now  pretending to come from BT  but actually coming from a different domain ebilling4business@btdnet.com   that can just about be mistaken for  a genuine BT email address is today’s latest spoof of a well-known company, bank or public authority delivering Dridex banking Trojan Continue reading → Continue reading Fake “Your latest BT OneBill is available now” malspam leads to Dridex banking trojan

Fake apple E-Invoice malspam delivers Locky Ransomware

The next in the never ending series of Locky downloaders is an email with the subject of  E-invoice for your order #6377810026 [ random numbers]pretending to come from do_not_reply@ random Apple email addresses . the addresses I have seen include: do_not_reply@eu.apple.com do_not_reply@asia.apple.com do_not_reply@us.apple.com   They use email addresses and subjects that will Continue reading → Continue reading Fake apple E-Invoice malspam delivers Locky Ransomware