Malicious Spam Campaign Dropping Malware
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
It is estimated that over 20,000 spam emails were sent, each containing a malicious attachment that leads to a malware infection. A number of samples collected were not detected by the vast majority of antivirus vendors, meaning an infection is likely to be successful if the malicious attachment is executed.
The email itself purports to be from the Federal trade Commission (FTC) with an attached subpoena. The attachment contains a XOR (exclusive or) key that is used to download malware from a compromised webserver acting as a Command and Control (C2).
A number of the C2 websites have been taken down by the attackers although some remain active. Along with hosting the malware binaries, the compromised web servers also host a file named ‘visitors.txt’ which logs the email addresses, attachment name and IP addresses of users with an active infection.
Remediation steps
Last edited: 17 February 2020 11:34 am