HomeSecurityPhishing campaign infects Windows computers with two types of trojan

Phishing campaign infects Windows computers with two types of trojan

PhishingA new phishing campaign is infecting victims with two popular trojans , and it seems the hackers are trying to target as many businesses as they can.

The phishing campaign began in April and was discovered by researchers at Netskope. Hackers are sending phishing emailsthat supposedly include an invoice and ask users to open an ISO file to see more details.

This ISO file carries the malicious payload, which is either LokiBot or Nanocore. Both malware provide attackers with backdoors into infected Windows computers, allowing them to steal dataand install other payloads.

Researchers said they have identified 10 variations of the campaign with different ISO images and emails .

 

The images sent are usually 1MB to 2MB, but inside they include an executable, which releases the actual malicious payload.

Phishing campaign infects Windows computers with two types of trojan

These days, most phishing campaignsthat use trojans to attack are becoming more targeted and attackers are developing increasingly sophisticated payloads. However, this particular campaign shows that even commercial malware used in simple phishing emailsstill poses a threat to organizations and companies.

This is especially true for department employees, who often need to open messages from unknown senders.

One of Netskope's researchers, Abhinav Singh, said that examination of the email and the attachment contained within showed that the hackers were primarily targeting company employees, particularly those working in the finance department. This suggests that the attackers were financially motivated.

The advice the researcher gives to users is to be very careful with any email that may seem suspicious and to pay even more attention to the attachments contained within, especially those that come from unreliable sources.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS