HomeSecurityUS Transportation and Logistics Companies Victims of Infostealer

US Transportation and Logistics Companies Victims of Infostealer

Hackers are targeting email accounts of shipping and transportation companies in North America to deliver various malware families, such as Infostealer, according to Proofpoint.

See also: Malicious League of Legends ads spread info-stealer malware

Infostealer companies

Since May 2024, malicious actors have been observed inserting malicious content into existing conversations within compromised company inboxes, to deliver infostealers such as Arechclient2, DanaBot, Lumma Stealer, NetSupport , and StealC.

Infostealers are a category of malware designed to covertly collect sensitive information from an infected device. Their primary target is personal data such as usernames, passwords, credit card details, and other financial information. Infostealers work by infiltrating a system through methods such as phishing attacks, malicious downloads, or compromised websites. Once in, they can monitor user activity or directly extract data from browser storage and system files. The stolen information is usually sent back to the attacker, who can use it for fraudulent purposes or sell it on the dark web.

Most Infostealer attacks rely on Google Drive URL links or files as attachments that execute a malicious payload to retrieve an executable file from a remote share and install malware, the cybersecurity firm says

See also: Infostealer bypasses Chrome's new cookie theft defenses

US Transportation and Logistics Companies Victims of Infostealer

To date, attackers have compromised approximately 15 email addresses, typically inserting fewer than 20 messages targeting a small number of transportation and logistics companies.

Proofpoint has seen threat actors mimic software commonly used to manage transportation and operations, such as Samsara, AMB Logistic , and Astra TMS.

According to the cybersecurity firm, while the observed techniques have been used by other adversaries in previous attacks, it is likely that the threat actor behind this campaign is “purchasing this infrastructure from third-party providers.”

To avoid falling victim to infostealer malware, Proofpoint recommends that companies in the transportation and supply chain sector be cautious when receiving emails from known senders that deviate from usual communication patterns and content, especially when they contain suspicious links and files.

See also: Marko Polo hackers target gamers/crypto users with info-stealer malware

The same goes for people working in other industries. When encountering suspicious emails, users should contact the sender to verify their authenticity.

Source: securityweek

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS