Skip to main content

Malicious Spam Campaign Dropping Malware

An on-going malicious spam campaign has been recently observed circulating information-stealing Trojans such as Vawtrak, Hancitor and Pony Loader.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

An on-going malicious spam campaign has been recently observed circulating information-stealing Trojans such as Vawtrak, Hancitor and Pony Loader.

Affected platforms

The following platforms are known to be affected:

Threat details

It is estimated that over 20,000 spam emails were sent, each containing a malicious attachment that leads to a malware infection. A number of samples collected were not detected by the vast majority of antivirus vendors, meaning an infection is likely to be successful if the malicious attachment is executed.

The email itself purports to be from the Federal trade Commission (FTC) with an attached subpoena. The attachment contains a XOR (exclusive or) key that is used to download malware from a compromised webserver acting as a Command and Control (C2).

A number of the C2 websites have been taken down by the attackers although some remain active. Along with hosting the malware binaries, the compromised web servers also host a file named ‘visitors.txt’ which logs the email addresses, attachment name and IP addresses of users with an active infection.


Remediation steps

Type Step
  • Monitor network and proxy logs for indicators of compromise.
  • Monitor email filters for emails containing the subject line.
  • Never open email attachments or click on links from untrusted sources.
  • Make sure that cyber-awareness training is kept up-to-date.

Last edited: 17 February 2020 11:34 am