Hackers are targeting email accounts of shipping and transportation companies in North America to deliver various malware families, such as Infostealer, according to Proofpoint.
See also: Malicious League of Legends ads spread info-stealer malware

Since May 2024, malicious actors have been observed inserting malicious content into existing conversations within compromised company inboxes, to deliver infostealers such as Arechclient2, DanaBot, Lumma Stealer, NetSupport , and StealC.
Infostealers are a category of malware designed to covertly collect sensitive information from an infected device. Their primary target is personal data such as usernames, passwords, credit card details, and other financial information. Infostealers work by infiltrating a system through methods such as phishing attacks, malicious downloads, or compromised websites. Once in, they can monitor user activity or directly extract data from browser storage and system files. The stolen information is usually sent back to the attacker, who can use it for fraudulent purposes or sell it on the dark web.
Most Infostealer attacks rely on Google Drive URL links or files as attachments that execute a malicious payload to retrieve an executable file from a remote share and install malware, the cybersecurity firm says
See also: Infostealer bypasses Chrome's new cookie theft defenses

To date, attackers have compromised approximately 15 email addresses, typically inserting fewer than 20 messages targeting a small number of transportation and logistics companies.
Proofpoint has seen threat actors mimic software commonly used to manage transportation and operations, such as Samsara, AMB Logistic , and Astra TMS.
According to the cybersecurity firm, while the observed techniques have been used by other adversaries in previous attacks, it is likely that the threat actor behind this campaign is “purchasing this infrastructure from third-party providers.”
To avoid falling victim to infostealer malware, Proofpoint recommends that companies in the transportation and supply chain sector be cautious when receiving emails from known senders that deviate from usual communication patterns and content, especially when they contain suspicious links and files.
See also: Marko Polo hackers target gamers/crypto users with info-stealer malware
The same goes for people working in other industries. When encountering suspicious emails, users should contact the sender to verify their authenticity.
Source: securityweek
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
