HomeSecurityFake Amazon emails distribute Banking Trojan

Fake Amazon emails distribute Banking Trojan

If you're one of those who rely on the e-commerce giant, also known as Amazon, to buy Christmas gifts, you should pay attention to the emails you will receive (or have received) from the company. EdgeWave has discovered a new malspam campaign that sends emails to random users to confirm a non-existent order.

The emails appear to be quite convincing, and include the subject lines “Your Amazon.com order,” “Amazon order details,” and “Your order 162-2672000-0034071 has shipped.”, which are the same as those used by the company.

According to BleepingComputer, when recipients open the email, they see an exact copy of the template Amazon uses, but without the item details. So the first thing they think to do is click on “Order Details” to find out more information.

Amazon

However, unsuspecting users are at great risk. By clicking on “Order Details”, they download a doc file named “order_details.doc”, in which to view the content they must click on “Enable Content”. Users who reach this point, allow a macro to run. The macro executes a powershell command which in turn downloads and executes the Emotet Banking Trojan.

Finally, EdgeWave researchers noticed that the Emotet Banking Trojan started executing as “keyandsymbol.exe” even though the Trojan’s name is “mergedboost.exe.” The servers hosting the banking trojan (where infected users connect to download it) are located in Houston and Lansing.

It is important BEFORE clicking on anything in an email to make sure of its origin, as well as its content.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS