Bezbedan Balkan
One of the largest agri-food exporters in Serbia being spoofed by a threat actor - Printable Version

+- Bezbedan Balkan (https://bezbedanbalkan.net)
+-- Forum: Bezbednost privatnih resursa (https://bezbedanbalkan.net/forum-12.html)
+--- Forum: Kompromitovani resursi (https://bezbedanbalkan.net/forum-13.html)
+--- Thread: One of the largest agri-food exporters in Serbia being spoofed by a threat actor (/thread-972.html)



One of the largest agri-food exporters in Serbia being spoofed by a threat actor - y0d4 - 11-17-2023

Quote:Symantec recently observed one of the largest agri-food exporters in Serbia being spoofed by a threat actor to target various organizations in the country. The malicious emails, written in Serbian (subject: Састанак за заказивање), have been crafted to appear as an invitation to set up a business appointment.

Attached to the email is a malicious .Z archive (Писмо састанка о именовању docx.z) – utilizing the Lempel-Ziv-Welch (LZW) compression algorithm. While this algorithm was commonly used in the past, it has been largely replaced by more efficient compression formats like .zip, .gzip, and .tar.gz. Nonetheless, Symantec continues to observe this type of archive being used by certain groups and individuals.

If users are successfully lured by this social engineering tactic and execute the malicious binary (Писмо састанка о именовању.docx.exe) within the archive, they'll end up running a NullSoft script-driven installer that will deploy a loader and an encrypted payload – Agent Tesla.


Source: https://www.broadcom.com/support/security-center/protection-bulletin?#bltcc0cddafa1975bf4_en-us


RE: one of the largest agri-food exporters in Serbia being spoofed by a threat actor - 1van - 11-17-2023

Za pretragu (IOC): "Састанак за заказивање", "Писмо састанка о именовању docx.z", "Писмо састанка о именовању.docx.exe", plus "DOMEN_AGRI_FOOD_KOMPANIJE Spam/Phishing".