HomeSecurityMalicious CV attachments distribute Ransomware

Malicious CV attachments distribute Ransomware

Ransomware emails

Security researchers warn of malicious CV attachments distributing the 3rd version of the Cryptowall Ransomware.

A new campaign of malicious emails, which appear to contain a CV of a prospective employee, has been detected by security researchers. The campaign aims to distribute the third version of the cryptowall ransomware, which has managed to bypass several antiviruses without detection.

 

Distributing crypto-malware in this way is nothing new, but cybercriminals make constant efforts to avoid detection by bypassing spam and malware detection mechanisms.

 

In this particular campaign, the email sent to victims appears to be a reply to a previous message sent by the victim themselves. Attached to the email is a zip file containing an html document.

 

This file redirects to a compromised WordPress website, which contains an iframe redirecting to a Google Drive cloud account, which delivers a malware downloader to users. The malware appears as a PDF, but is actually an executable (SCR) file.

 

Cisco security and research specialist Nick Biasini and his team analyzed the infection chain and concluded that many users downloaded the malware attached to the email. The researcher also cited as an example that “if the malicious email is sent to someone who has started the recruitment and candidate assessment processes, then it is very likely that they will open the attachment.”.

 

Despite the fact that cryptowall is well known in the security industry, it is distributed with minor variations, thus avoiding detection.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS