HomeSecurityMulti-year phishing campaign targets German automakers

Multi-year phishing campaign targets German automakers

A multi-year phishing campaign is targeting German automakers, attempting to infect their systems with password-stealing malware.

Multi-year phishing campaign targets German automakers

Targets include car manufacturers and car dealerships in Germany, and the threat actors have registered multiple similar domains for use in their operation, cloning legitimate sites of various organizations in this sector.

These websites are used to send phishing emails written in German and host the malware payloads downloaded to targeted systems.

Check Point researchers discovered this campaign and published a technical report detailing their findings. According to the report, the campaign began around July 2021 and is still ongoing.

Multi-year phishing campaign targets German automakers

Targeting German car manufacturers

The infection chain begins with an email sent to specific targets containing an ISO disk image file that bypasses many Internet.

For example, the phishing email below pretends to contain a car transfer receipt sent to a targeted dealership.

Multi-year phishing campaign targets German automakers

This file, in turn, contains an .HTA file that contains JavaScript or VBScript code execution via HTML smuggling.

Multi-year phishing campaign targets German automakers

This is a common technique used by hackers of all skill levels, from “script kiddies” who rely on automated kits to state-sponsored hackers who develop custom backdoors.

While the victim views a decoy document opened from the HTA file, the malicious code runs in the background to retrieve the malware payloads and launch them.

Multi-year phishing campaign targets German automakers

The MaaS info-stealers used in this campaign vary, including Raccoon Stealer, AZORult, and BitRAT. All three are available for purchase on cybercrime marketplaces and darknet forums.

In newer versions of the HTA file, PowerShell code is executed to change registry values ​​and enable content in the Microsoft Office. This makes it unnecessary for threat actors to trick the recipient into enabling macros and improves the payload drop rate.

German car manufacturers

Goals and performance

Check Point says it could trace these attacks to 14 targeted entities, all of which were German organizations with some connection to the automotive industry. However, the report does not name specific companies.

The information-stealing payloads were hosted on a website (“bornagroup[.]ir”) registered by an Iranian, while the same email was used for phishing subdomains such as “groupschumecher[.]com”.

Threat analysts were able to find links to a different phishing operation targeting Santander Bank customers, with sites supporting this campaign being hosted on an Iranian internet service provider.

German car manufacturers

In summary, there is a strong possibility that Iranian threat actors are orchestrating the campaign, but Check Point does not have enough evidence to attribute responsibility there.

Finally, regarding the campaign's objectives, it is likely industrial espionage or BEC (business email compromise), directed against these companies or their customers, suppliers , and contractors .

Emails sent to targets leave a lot of room for correspondence, so building a relationship with the victim and gaining their trust is a likely scenario that lends credibility to the BEC case.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS