One of the largest agri-food exporters in Serbia being spoofed by a threat actor
#1
Quote:Symantec recently observed one of the largest agri-food exporters in Serbia being spoofed by a threat actor to target various organizations in the country. The malicious emails, written in Serbian (subject: Састанак за заказивање), have been crafted to appear as an invitation to set up a business appointment.

Attached to the email is a malicious .Z archive (Писмо састанка о именовању docx.z) – utilizing the Lempel-Ziv-Welch (LZW) compression algorithm. While this algorithm was commonly used in the past, it has been largely replaced by more efficient compression formats like .zip, .gzip, and .tar.gz. Nonetheless, Symantec continues to observe this type of archive being used by certain groups and individuals.

If users are successfully lured by this social engineering tactic and execute the malicious binary (Писмо састанка о именовању.docx.exe) within the archive, they'll end up running a NullSoft script-driven installer that will deploy a loader and an encrypted payload – Agent Tesla.


Source: https://www.broadcom.com/support/securit...5bf4_en-us
Reply
#2
Za pretragu (IOC): "Састанак за заказивање", "Писмо састанка о именовању docx.z", "Писмо састанка о именовању.docx.exe", plus "DOMEN_AGRI_FOOD_KOMPANIJE Spam/Phishing".
“If you think you are too small to make a difference, try sleeping with a mosquito.” - Dalai Lama XIV
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)