Proofpoint researchers have identified a low-volume ransomware email campaign targeting organizations/companies in Austria, Switzerland, and Germany. The campaign leverages Hakbit, a variant of Thanos ransomware as a service (RaaS). The attack uses malicious Microsoft Excel attachments delivered by a free email provider (GMX) that primarily serves a European customer base. The attachments contain fake billing and tax refund topics to entice users to activate macros that execute GuLoader, which downloads the ransomware to encrypt files and lock down the system.

To ensure success because Microsoft Office VBA macros do not run on mobile devices, these emails direct recipients to open the attachments on their computer, not their mobile device.
Targeted users were employed in mid-level positions in the pharmaceutical, legal, financial, business services, retail, and healthcare industries. The largest volume of messages we observed were sent to the IT, manufacturing, insurance, and technology. Proofpoint researchers have observed that the majority of roles targeted in campaigns are customer-facing with contact information publicly disclosed on company websites and/or advertisements. These roles include lawyers, client advisors, directors, insurance consultants, CEOs, and project managers.
Below is an example of the messages users receive, which often have the following subjects “Fwd: Steuerrückzahlung” (Translation: Tax Refund) and “Ihre Rechnung (Translation: Your Bill)”.

This message is in German and misuses the logo and brand of 1&1, a German telecommunications company. According to Google Translate, the message reads:

The message contains a Microsoft Excel attachment named 379710.xlsm that leverages malicious macros. Because macros and malware will not work on a mobile device, the message instructs the recipient to use a computer to read the attachment. Once opened, the spreadsheet directs the recipient in German and English to enable macros, as shown in Figure 2.

Once the macros are enabled in the spreadsheet, it downloads and executes GuLoader, a relatively new downloader. When GuLoader is executed, it downloads and executes Hakbit, a ransomware that encrypts files using AES-256 encryption.
Below is the image that appears when Hakbit is running (Figure 3) and also see the ransom note in English and German (Figure 4).


The note demands 250 euros in bitcoin to unlock the encrypted files and provides instructions on how to pay the ransom.
Conclusion
Proofpoint researchers have observed consistent, low-volume and frequent ransomware campaigns since January 2020. Proofpoint researchers recently identified a shift in the threat landscape with a large Avaddon ransomware campaign according to recent reports.
Of course, we should note that some other security companies report that the ransomware is called Thanos, so be careful about its name.
