A malicious email was recently detected by researchers at CSIS Security Group and uses the organization's name as a lure to lure recipients into malware.

CSI is a Danish security company that provides security services to some of the largest banks operating globally. The company also provides security consulting to governments, media and businesses.
There isn't much evidence available at this time as the investigation into the campaign is still ongoing, but researchers did spot an email with a malicious attachment that spoofed the company's email address and used the name of Peter Kruse, a security expert at CSIS.
Written in English, the message is poorly written and contains abundant grammatical errors that should raise suspicions even in the least suspicious of individuals.
It informs the recipient that an email sent from their address contained malware discovered by CSI and that a tool designed to clean their system is attached.
The email contains a ZIP, 11kb in size, but there is no information about the nature of the malware it downloads when executed.
CSIS issued an apology to users who received the fake message and advised that they were not the senders of the message. The company promised to publish more details about the issue, such as the progress of the investigation, and advised recipients to delete the email immediately upon receiving it.
