Malware-ransomware combo campaign hits North American inboxes
An updated version of a popular credential-stealing malware variant has been paired with ransomware to send thousands of emails in North America, according to new research. Within a day of hackers releasing an update of the trojan malware known as AZORult to underground forums, a “prolific actor” had coupled it with the Hermes ransomware, according to research from email security company Proofpoint. The hybrid malware campaign targeted email users with job-related subject lines that came with malicious attachments, Proofpoint said. The company attributed the campaign to a hacking group it dubbed TA516, which has used similar tricks to install banking trojans or a Monero cryptocurrency miner. The Hermes 2.1 variant used in the attack first emerged in November 2017 and was used in an attack on a Taiwanese bank that has been linked with North Korea. However, there isn’t any evidence to suggest at this point that TA516 is linked […]
The post Malware-ransomware combo campaign hits North American inboxes appeared first on Cyberscoop.
Continue reading Malware-ransomware combo campaign hits North American inboxes