Recently, researchers at security firm Cofense discovered a new hacking campaign targeting employees of insurance companies and retail industries. Hackers send phishing emails to employees claiming to be from the Department of Justice. In reality, they infect the victim’s computer with malware designed to steal information.
According to the researchers, the phishing emails have the word “ Court ” in the subject line and bear the logo of the UK Ministry of Justice. The emails state that the recipient must appear in court as a witness (subpoena) and ask them to open a link to see more details, as the court orders the matter to be resolved within 14 days. However, no specific information is given about the subject of the court case.
Opening the link leads to a cloud hosting provider, which in turn, leads the user to a document containing "Predator The Thief", a malware commonly found on underground hacking forums.
Predator the Thief is a malware that allows the theft of usernames, passwords, browser data, and content from cryptocurrency wallets. It can also take photos using a webcam. Predator the Thief first appeared in July 2018.

Hackers have made sure that phishing emails hide their malicious intent from security software. The email contains a link to Google Docs, which automatically redirects the user to Microsoft OneDrive, which in turn delivers a Microsoft Word document to the victim. The document asks the victim to enable macros. If the user complies, the malware is downloaded via PowerShell.
Predator the Thief then connects to a command-and-control server and provides the hacker with a gateway into the infected system. This allows attackers to steal data covertly. Once all the data the hackers want is collected, the malware self-destructs , leaving no trace.
As in most phishing attacks, the hackers used a serious issue (a legal matter) to force victims to open the malicious link. However, there is a sign that something is wrong.
The phishing email mentions the word “subpoena.” This term is commonly used in the United States. The email purports to come from the United Kingdom’s Department of Justice. However, the English judicial system has not used the term “subpoena” since 1999. Since then, only the term “witness summons” has been used.
This shows that the perpetrators are trying to scam users by using British logos but are actually unfamiliar with the country's judicial system.
Users should be very careful with enabling macros and constantly stay informed about cyber risks and threats , so that they are aware and can recognize suspicious activities.
