Spyware, dubbed Anomalous by security researchers, appears to be targeting industrial companies with the aim of stealing credentials. Researchers have discovered several spyware targeting industrial companies with the aim of stealing email credentials to commit financial fraud or resell them to other malicious actors.

See also: Is the Greek government spying on citizens through Predator spyware?
Malicious users use spyware tools and deploy variants for a very limited time in order to avoid detection.
Examples of malware used in such attacks include AgentTesla/Origin Logger, HawkEye, Noon/Formbook, Masslogger, Snake Keylogger, Azorult , and Lokibot.
Kaspersky - lived nature compared to what is considered typical in their field.
More specifically, the lifespan of the attacks is limited to approximately 25 days, while most spyware campaigns last several months or even years.
The number of systems attacked in these campaigns is always under a hundred, half of which are ICS (integrated computing systems) machines deployed in industrial environments.
Another unusual element is the use of the SMTP-based communication protocol to export data to the C2 server controlled by the malicious users.
See also: PhoneSpy: Android spyware campaign targets Korean users
Unlike HTTPS, which is used in most typical spyware campaigns for C2 communication, SMTP is a one-way channel that serves exclusively to steal data.

SMTP is not a common choice for malicious actors, as it cannot retrieve binary or other non-text files, but it thrives thanks to its simplicity and ability to blend in with normal network traffic.
Malicious users use stolen employee credentials obtained through spear-phishing to penetrate deeper into the company's network and move laterally.
Additionally, they use corporate mailboxes that have been compromised in previous attacks as C2 servers, making it very difficult to detect and flag malicious internal mail.
In terms of numbers, analysts identified at least 2,000 corporate email accounts that were abused as temporary C2 servers and another 7,000 email accounts that were abused in other ways.
See also: Diavol ransomware spreads via email and steals money
Many of the RDP, SMTP, SSH, cPanel, and VPN email account credentials stolen in these campaigns are made available on dark web marketplaces and ultimately sold to other malicious users.
According to statistical analysis , approximately 3.9% of all RDP accounts sold on these illegal markets belong to industrial companies.
RDP (Remote Desktop Protocol) accounts are valuable to cybercriminals because they enable them to remotely access compromised machines and interact directly with a device without being detected.
