A multi-year phishing campaign is targeting German automakers, attempting to infect their systems with password-stealing malware.

Targets include car manufacturers and car dealerships in Germany, and the threat actors have registered multiple similar domains for use in their operation, cloning legitimate sites of various organizations in this sector.
These websites are used to send phishing emails written in German and host the malware payloads downloaded to targeted systems.
Check Point researchers discovered this campaign and published a technical report detailing their findings. According to the report, the campaign began around July 2021 and is still ongoing.
Targeting German car manufacturers
The infection chain begins with an email sent to specific targets containing an ISO disk image file that bypasses many Internet.
For example, the phishing email below pretends to contain a car transfer receipt sent to a targeted dealership.

This file, in turn, contains an .HTA file that contains JavaScript or VBScript code execution via HTML smuggling.

This is a common technique used by hackers of all skill levels, from “script kiddies” who rely on automated kits to state-sponsored hackers who develop custom backdoors.
While the victim views a decoy document opened from the HTA file, the malicious code runs in the background to retrieve the malware payloads and launch them.

The MaaS info-stealers used in this campaign vary, including Raccoon Stealer, AZORult, and BitRAT. All three are available for purchase on cybercrime marketplaces and darknet forums.
In newer versions of the HTA file, PowerShell code is executed to change registry values and enable content in the Microsoft Office. This makes it unnecessary for threat actors to trick the recipient into enabling macros and improves the payload drop rate.

Goals and performance
Check Point says it could trace these attacks to 14 targeted entities, all of which were German organizations with some connection to the automotive industry. However, the report does not name specific companies.
The information-stealing payloads were hosted on a website (“bornagroup[.]ir”) registered by an Iranian, while the same email was used for phishing subdomains such as “groupschumecher[.]com”.
Threat analysts were able to find links to a different phishing operation targeting Santander Bank customers, with sites supporting this campaign being hosted on an Iranian internet service provider.

In summary, there is a strong possibility that Iranian threat actors are orchestrating the campaign, but Check Point does not have enough evidence to attribute responsibility there.
Finally, regarding the campaign's objectives, it is likely industrial espionage or BEC (business email compromise), directed against these companies or their customers, suppliers , and contractors .
Emails sent to targets leave a lot of room for correspondence, so building a relationship with the victim and gaining their trust is a likely scenario that lends credibility to the BEC case.
Information source: bleepingcomputer.com

