
Malicious actors, using members of the Maze ransomware family, target users from Italy.
According to security researcher JAMESWT’s discovery, the malicious campaign is targeting users in Italy through emails purporting to come from the Agenzia delle Entrate, or Italian revenue agency. The text of the message informs recipients that they should start complying with new guidelines issued by the agency. The email includes an attachment called “VERDI.doc,” which the text claims describes these new guidelines.
Once the user opens the “VERDI.doc” file, they are informed that its contents are encrypted with the RSA encryption algorithm and that they will need to “Enable Content” to see the new instructions. Users who agree unknowingly execute an embedded macro that downloads a Maze strain to device .
Maze is a relatively new threat that has so far attracted the attention of the securitydue to various exploit kits for distribution. In July, for example, Cisco Talos discovered attackers using the Fallout exploit kit to spread the ransomware. It was only a few months later that Bleeping Computer discovered a campaign in which the Spelevo exploit kit used a flaw in Flash Player to distribute Maze.
In a more recent attack, ransomware encrypted the computer and changed the desktop background to display a ransom note. This message asked the victim to visit a payment website to purchase a decryption key.
In its analysis, Bleeping Computer found that the operators of Maze were demanding 1,200 dollars as ransom.
There is no way for Maze victims to recover their files for free at this time, so you must always be cautious with emails received, even if they appear to come from known organizations or companies, and not reply to or open any attachments that may contain them.
