home.social

#malspam — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #malspam, aggregated by home.social.

  1. LokiBot After a Decade: An Analysis of a Recent LokiBot Campaign

    LokiBot, an infostealer first advertised in May 2015, continues to operate after more than a decade with numerous variants. The malware targets credentials from over a hundred software products including browsers, cryptocurrency wallets, password managers, email and FTP clients. A recent campaign delivers LokiBot through malspam with JScript email attachments, executing a multi-stage infection chain involving PowerShell loaders and .NET injectors protected by ConfuserEx. The final payload uses process injection into aspnet_compiler.exe, employing API hashing techniques to evade detection. While LokiBot maintains extensive credential theft capabilities, recent samples exhibit broken persistence mechanisms due to patched decryption subroutines. The malware communicates with C2 servers to exfiltrate compressed stolen data and await further commands, demonstrating continued evolution despite reduced activity in recent years.

    Pulse ID: 6a3c6b9416a51c4cdec616c4
    Pulse Link: otx.alienvault.com/pulse/6a3c6
    Pulse Author: AlienVault
    Created: 2026-06-24 23:43:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ASPNet #ASPNet_Compiler #Browser #CyberSecurity #Email #InfoSec #InfoStealer #MalSpam #Malware #NET #OTX #OpenThreatExchange #Password #PowerShell #RAT #SMS #Spam #Word #bot #cryptocurrency #AlienVault

  2. LokiBot After a Decade: An Analysis of a Recent LokiBot Campaign

    LokiBot, an infostealer first advertised in May 2015, continues to operate after more than a decade with numerous variants. The malware targets credentials from over a hundred software products including browsers, cryptocurrency wallets, password managers, email and FTP clients. A recent campaign delivers LokiBot through malspam with JScript email attachments, executing a multi-stage infection chain involving PowerShell loaders and .NET injectors protected by ConfuserEx. The final payload uses process injection into aspnet_compiler.exe, employing API hashing techniques to evade detection. While LokiBot maintains extensive credential theft capabilities, recent samples exhibit broken persistence mechanisms due to patched decryption subroutines. The malware communicates with C2 servers to exfiltrate compressed stolen data and await further commands, demonstrating continued evolution despite reduced activity in recent years.

    Pulse ID: 6a3c6b9416a51c4cdec616c4
    Pulse Link: otx.alienvault.com/pulse/6a3c6
    Pulse Author: AlienVault
    Created: 2026-06-24 23:43:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ASPNet #ASPNet_Compiler #Browser #CyberSecurity #Email #InfoSec #InfoStealer #MalSpam #Malware #NET #OTX #OpenThreatExchange #Password #PowerShell #RAT #SMS #Spam #Word #bot #cryptocurrency #AlienVault

  3. LokiBot After a Decade: An Analysis of a Recent LokiBot Campaign

    LokiBot, an infostealer first advertised in May 2015, continues to operate after more than a decade with numerous variants. The malware targets credentials from over a hundred software products including browsers, cryptocurrency wallets, password managers, email and FTP clients. A recent campaign delivers LokiBot through malspam with JScript email attachments, executing a multi-stage infection chain involving PowerShell loaders and .NET injectors protected by ConfuserEx. The final payload uses process injection into aspnet_compiler.exe, employing API hashing techniques to evade detection. While LokiBot maintains extensive credential theft capabilities, recent samples exhibit broken persistence mechanisms due to patched decryption subroutines. The malware communicates with C2 servers to exfiltrate compressed stolen data and await further commands, demonstrating continued evolution despite reduced activity in recent years.

    Pulse ID: 6a3c6b9416a51c4cdec616c4
    Pulse Link: otx.alienvault.com/pulse/6a3c6
    Pulse Author: AlienVault
    Created: 2026-06-24 23:43:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ASPNet #ASPNet_Compiler #Browser #CyberSecurity #Email #InfoSec #InfoStealer #MalSpam #Malware #NET #OTX #OpenThreatExchange #Password #PowerShell #RAT #SMS #Spam #Word #bot #cryptocurrency #AlienVault

  4. LokiBot After a Decade: An Analysis of a Recent LokiBot Campaign

    LokiBot, an infostealer first advertised in May 2015, continues to operate after more than a decade with numerous variants. The malware targets credentials from over a hundred software products including browsers, cryptocurrency wallets, password managers, email and FTP clients. A recent campaign delivers LokiBot through malspam with JScript email attachments, executing a multi-stage infection chain involving PowerShell loaders and .NET injectors protected by ConfuserEx. The final payload uses process injection into aspnet_compiler.exe, employing API hashing techniques to evade detection. While LokiBot maintains extensive credential theft capabilities, recent samples exhibit broken persistence mechanisms due to patched decryption subroutines. The malware communicates with C2 servers to exfiltrate compressed stolen data and await further commands, demonstrating continued evolution despite reduced activity in recent years.

    Pulse ID: 6a3c6b9416a51c4cdec616c4
    Pulse Link: otx.alienvault.com/pulse/6a3c6
    Pulse Author: AlienVault
    Created: 2026-06-24 23:43:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ASPNet #ASPNet_Compiler #Browser #CyberSecurity #Email #InfoSec #InfoStealer #MalSpam #Malware #NET #OTX #OpenThreatExchange #Password #PowerShell #RAT #SMS #Spam #Word #bot #cryptocurrency #AlienVault

  5. LokiBot After a Decade: An Analysis of a Recent LokiBot Campaign

    LokiBot, an infostealer first advertised in May 2015, continues to operate after more than a decade with numerous variants. The malware targets credentials from over a hundred software products including browsers, cryptocurrency wallets, password managers, email and FTP clients. A recent campaign delivers LokiBot through malspam with JScript email attachments, executing a multi-stage infection chain involving PowerShell loaders and .NET injectors protected by ConfuserEx. The final payload uses process injection into aspnet_compiler.exe, employing API hashing techniques to evade detection. While LokiBot maintains extensive credential theft capabilities, recent samples exhibit broken persistence mechanisms due to patched decryption subroutines. The malware communicates with C2 servers to exfiltrate compressed stolen data and await further commands, demonstrating continued evolution despite reduced activity in recent years.

    Pulse ID: 6a3c6b9416a51c4cdec616c4
    Pulse Link: otx.alienvault.com/pulse/6a3c6
    Pulse Author: AlienVault
    Created: 2026-06-24 23:43:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ASPNet #ASPNet_Compiler #Browser #CyberSecurity #Email #InfoSec #InfoStealer #MalSpam #Malware #NET #OTX #OpenThreatExchange #Password #PowerShell #RAT #SMS #Spam #Word #bot #cryptocurrency #AlienVault

  6. Trust this “Amazon” phishing email in Japan—and you’re Prime sashimi 🎣 🍣

    Looking into our malspam data, we identified an active campaign impersonating Amazon and targeting Japanese citizens. The emails use subjects such as 「至急 Amazonプライム会員情報の確認」 (“Urgent: Confirm Amazon Prime member information”).

    The URLs within the emails ultimately lead to an Amazon phishing page, but only after routing victims through a TDS. Interestingly, instead of keeping the TDS step invisible, the actors chose to show it off—repackaging it as a reassuring security check.

    Upon clicking the link within the email, victims are first redirected to an RDGA TDS domain, where fingerprinting occurs. If the user does not match the targeting criteria (e.g., connecting from outside Japan), access is blocked. If they do match, potential victims are redirected to a second RDGA domain.
    This second and last domain is not a TDS domain, but funny enough, these actors decided they would emulate it anyway!

    At that step victims are already at the landing page but instead of immediately displaying a standard Amazon phishing page, the website displays a CAPTCHA and fake console interface simulating environment fingerprinting checks to “make sure your environment and connection is safe” before "proceeding to the landing page". Ironically, part of their message is true: fingerprinting did happen one domain earlier. It just wasn’t for the user’s benefit—it was to make sure the environment was safe… for the scammers. A few seconds later, without added user interaction needed, a fake Amazon login page is displayed.

    Domains samples:
    qqc10c[.]cyou
    51wang11c[.]cyou

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #phishing #amazon #malspam #email #fingerprinting #japan

  7. Trust this “Amazon” phishing email in Japan—and you’re Prime sashimi 🎣 🍣

    Looking into our malspam data, we identified an active campaign impersonating Amazon and targeting Japanese citizens. The emails use subjects such as 「至急 Amazonプライム会員情報の確認」 (“Urgent: Confirm Amazon Prime member information”).

    The URLs within the emails ultimately lead to an Amazon phishing page, but only after routing victims through a TDS. Interestingly, instead of keeping the TDS step invisible, the actors chose to show it off—repackaging it as a reassuring security check.

    Upon clicking the link within the email, victims are first redirected to an RDGA TDS domain, where fingerprinting occurs. If the user does not match the targeting criteria (e.g., connecting from outside Japan), access is blocked. If they do match, potential victims are redirected to a second RDGA domain.
    This second and last domain is not a TDS domain, but funny enough, these actors decided they would emulate it anyway!

    At that step victims are already at the landing page but instead of immediately displaying a standard Amazon phishing page, the website displays a CAPTCHA and fake console interface simulating environment fingerprinting checks to “make sure your environment and connection is safe” before "proceeding to the landing page". Ironically, part of their message is true: fingerprinting did happen one domain earlier. It just wasn’t for the user’s benefit—it was to make sure the environment was safe… for the scammers. A few seconds later, without added user interaction needed, a fake Amazon login page is displayed.

    Domains samples:
    qqc10c[.]cyou
    51wang11c[.]cyou

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #phishing #amazon #malspam #email #fingerprinting #japan

  8. New 2026 telemetry from Bitdefender indicates 41% of Valentine’s-themed email traffic contained scam elements.

    Threat vectors observed:
    • Brand impersonation campaigns
    • AI-generated dating personas
    • Advance-fee survey funnels
    • Delivery notification phishing
    • Pharma spam distribution
    • Healthcare provider impersonation (e.g., Techniker Krankenkasse)
    Geographic targeting concentrated in the U.S. (55%) and key European markets.

    Question for defenders:
    Are current email filtering models sufficiently adaptive to seasonal emotional triggers amplified by generative AI?
    Engage below.

    Follow @technadu for threat intelligence reporting.

    #ThreatIntel #Phishing #EmailSecurity #AIThreats #SOC #BlueTeam #FraudDetection #BrandAbuse #SecurityResearch #CyberDefense #Malspam #DigitalRisk

  9. If you've been experiencing these new #malspam with @Action1corp #action1 RMM, there's a tasty lil file called C:\Windows\Action1\what_is_this.txt that's everything you need to know:
    app.any.run/tasks/a38ca435-f03

  10. It sometimes pays to run domains that serve purely as spam honeypots. Case in point: A spammer has been delivering a ConnectWise commercial remote access client application as a payload in a scam that uses the purported arrival of a US Social Security statement as its hook.

    A 🧵 ...

    #ConnectWise #malware #spam #malspam #attacksurface #SocialSecurity #SocialSecurityAdministration #SSA #usgov

  11. It sometimes pays to run domains that serve purely as spam honeypots. Case in point: A spammer has been delivering a ConnectWise commercial remote access client application as a payload in a scam that uses the purported arrival of a US Social Security statement as its hook.

    A 🧵 ...

    #ConnectWise #malware #spam #malspam #attacksurface #SocialSecurity #SocialSecurityAdministration #SSA #usgov

  12. #MalspamMonday

    Malspam Monday is when I check the inboxes of my honey pot accounts for anything interesting distributed through email.

    Today, I found an example of #GuLoader for #Remcos #RAT

    Details at github.com/malware-traffic/ind

    #RemcosRAT #malspam

  13. #MalspamMonday

    Malspam Monday is when I check the inboxes of my honey pot accounts for anything interesting distributed through email.

    Today, I found an example of #GuLoader for #Remcos #RAT

    Details at github.com/malware-traffic/ind

    #RemcosRAT #malspam

  14. 2025-03-05 (Wednesday): #Astaroth ( #Guildma ) distributed through Brazil #malspam

    As usual, I didn't get a full infection chain, but I did get the initial zip archive from that link in the email.

    Details at github.com/malware-traffic/ind

  15. 2025-03-05 (Wednesday): #Astaroth ( #Guildma ) distributed through Brazil #malspam

    As usual, I didn't get a full infection chain, but I did get the initial zip archive from that link in the email.

    Details at github.com/malware-traffic/ind

  16. ⚠️ Uwaga na e-maile z kancelarii prawnych

    Na skrzynki Polaków znów trafiają pisma, w których oszuści podszywają się pod różne znane kancelarie prawne. Wiadomości informują o naruszeniu praw autorskich i wyglądają profesjonalnie. Zawierają też link do skanu pisma z “dowodami naruszeń praw autorskich”.

    I to właśnie kliknięcie na ten link, pobranie oraz uruchomienie podlinkowanych plików może spowodować infekcję komputera złośliwym oprogramowaniem oraz — w konsekwencji — kradzież danych oraz stratę kont w serwisach społecznościowych. Na atak powinni uważać zwłaszcza posiadacze kont na Facebooku.
    Po czym rozpoznać, że to oszustwo? E-maile są wysyłane z różnych adresów w domenie GMail. Link do pisma z dowodami, wbrew opisowi, nie prowadzi do PDF. I na marginesie — choć otrzymanie wiadomości o naruszeniu praw autorskich może wywołać stres, to warto mieć świadomość, że poważna korespondencja z kancelarii prawnych, jeśli ma być wiążąca, powinna dotrzeć do nas w formie papierowej.
    Otrzymałem taką wiadomość — co robić, jak żyć?

    Jeśli otrzymałeś taką wiadomość, nic nie musisz robić. Możesz ją zignorować. Żadne Twoje dane nie wyciekły, a żadna z opublikowanych przez Ciebie treści nie naruszyła praw autorskich innych firm.
    Jeśli tylko pobrałeś załącznik — nie zostałeś zainfekowany.

    Jeśli pobrałeś załącznik, rozpakowałeś go i uruchomiłeś aplikację z załącznika, to jak najszybciej poddaj swój komputer analizie pod kątem złośliwego oprogramowania z innego urządzenia zaloguj się na wszystkie istotne konta oraz zmień na nich hasła, a tam gdzie to możliwe, wyloguj również “pozostałe sesje/urządzenia”.

    To ostrzeżenie wysłaliśmy także jako alert do użytkowników naszej bezpłatnej aplikacji CyberAlerty. Jeśli też chcesz być informowany o atakach, [...]

    #Cyberalert #Malspam #PrawaAutorskie #SpearPhishing

    niebezpiecznik.pl/post/uwaga-n

  17. ⚠️ Uwaga na e-maile z kancelarii prawnych

    Na skrzynki Polaków znów trafiają pisma, w których oszuści podszywają się pod różne znane kancelarie prawne. Wiadomości informują o naruszeniu praw autorskich i wyglądają profesjonalnie. Zawierają też link do skanu pisma z “dowodami naruszeń praw autorskich”.

    I to właśnie kliknięcie na ten link, pobranie oraz uruchomienie podlinkowanych plików może spowodować infekcję komputera złośliwym oprogramowaniem oraz — w konsekwencji — kradzież danych oraz stratę kont w serwisach społecznościowych. Na atak powinni uważać zwłaszcza posiadacze kont na Facebooku.
    Po czym rozpoznać, że to oszustwo? E-maile są wysyłane z różnych adresów w domenie GMail. Link do pisma z dowodami, wbrew opisowi, nie prowadzi do PDF. I na marginesie — choć otrzymanie wiadomości o naruszeniu praw autorskich może wywołać stres, to warto mieć świadomość, że poważna korespondencja z kancelarii prawnych, jeśli ma być wiążąca, powinna dotrzeć do nas w formie papierowej.
    Otrzymałem taką wiadomość — co robić, jak żyć?

    Jeśli otrzymałeś taką wiadomość, nic nie musisz robić. Możesz ją zignorować. Żadne Twoje dane nie wyciekły, a żadna z opublikowanych przez Ciebie treści nie naruszyła praw autorskich innych firm.
    Jeśli tylko pobrałeś załącznik — nie zostałeś zainfekowany.

    Jeśli pobrałeś załącznik, rozpakowałeś go i uruchomiłeś aplikację z załącznika, to jak najszybciej poddaj swój komputer analizie pod kątem złośliwego oprogramowania z innego urządzenia zaloguj się na wszystkie istotne konta oraz zmień na nich hasła, a tam gdzie to możliwe, wyloguj również “pozostałe sesje/urządzenia”.

    To ostrzeżenie wysłaliśmy także jako alert do użytkowników naszej bezpłatnej aplikacji CyberAlerty. Jeśli też chcesz być informowany o atakach, [...]

    #Cyberalert #Malspam #PrawaAutorskie #SpearPhishing

    niebezpiecznik.pl/post/uwaga-n

  18. 2025-02-25 (Tuesday): #VenomRAT from #malspam uses zip attachment containing a VHD file containing a VBS file. Calls Pastebin link for C2 server information. Details at github.com/malware-traffic/ind

  19. 2025-02-25 (Tuesday): #VenomRAT from #malspam uses zip attachment containing a VHD file containing a VBS file. Calls Pastebin link for C2 server information. Details at github.com/malware-traffic/ind

  20. 🔍 Campagne #Malware in Italia – Week 45 🔎
    #Remcos: Transazioni bancarie
    #Irata / #BingoMod / #ToxicPanda: APK Bank
    #AgentTesla: Ordini
    #SnakeKeyLogger: Preventivo
    #XWorm: Fatturazione
    #Formbook: Contratto
    #Vidar: Fattura via PEC
    #VipKeyLogger: Ordini
    #mwitaly #malspam

  21. ⚠️ Attenzione: Nuova campagna malware #Guloader - #Formbook in Italia!

    Stanno circolando email con falsi termini di contratto che mirano a trarre in inganno gli utenti.

    🔍 IoC: ca0415559d7f7c869f5bf3b54070046c

    Resta vigile, non aprire allegati sospetti!

    #mwitaly #malspam

  22. 🐍 Allerta #SnakeKeyLogger in Italia 🐍

    #Malware diffuso tramite email di Sollecito Pagamento

    🧩 IoC principali:
    - MD5: 16e3b155eaf7d1979f651c9d8212c713
    - C2: mail.]el-rohim.]com

    Resta vigile, non aprire allegati sospetti!

    #mwitaly #malspam

  23. ⚠️ Nuova campagna #malspam con oggetto: “Specifiche dell’ordine” veicola #malware #ZharkBOT!

    La mail contiene un file HTML che scarica un file VBS malevolo.

    MD5: ca8ac9a5b0023d32bcd76c65512a6cd3

    ℹ️ Tutti gli IoC sono disponibili su #Telegram: t.me/D3LabIT

  24. ⚠️ Attenzione ⚠️

    Nuova campagna #malspam con oggetto: “Conferma dell’ordine”. Il #malware appartiene alla famiglia #Formbook.

    ℹ️ Tutti gli IoC sono disponibili nel nostro canale Telegram: t.me/D3LabIT

    #cybersecurity #threatintel #malware #mwitaly #italy

  25. ⚠️ Attenzione ⚠️

    Nuova campagna #malspam con oggetto: “Conferma dell’ordine”. Il #malware appartiene alla famiglia #Formbook.

    ℹ️ Tutti gli IoC sono disponibili nel nostro canale Telegram: t.me/D3LabIT

    #cybersecurity #threatintel #malware #mwitaly #italy

  26. ⚠️ Attenzione ⚠️

    Nuova campagna #malspam con oggetto: “Conferma dell’ordine”. Il #malware appartiene alla famiglia #Formbook.

    ℹ️ Tutti gli IoC sono disponibili nel nostro canale Telegram: t.me/D3LabIT

    #cybersecurity #threatintel #malware #mwitaly #italy

  27. ⚠️ Attenzione ⚠️

    Nuova campagna #malspam "Distinta Pagamento Bonifico".

    🛡️ Il #malware appartiene alla famiglia #VIPKeylogger

    📎 #IoC: 9dec40122bbd2f9865c57df3b07e97b1

    ℹ️ Tutti gli IoC sono disponibili nel nostro canale Telegram: t.me/D3LabIT

    #threatintel

  28. Why you need an infosec analyst on your #SchoolBoard: I received two scam emails this past weekend on an account I use for my candidacy and alerted my fellow candidates.

    The scams were fairly rudimentary "iTunes gift card" fraud, but the attackers did look for and use the names of other candidates and one actual board member in their scam emails.

    I had heard that politicians get hit with a larger-than-average volume of #malspam but this was a new one for me. Also, totally hamfisted, using UTC+3 time zone and a Russia-based webmail provider. Try harder next time, losers!

    #ElectMoreHackers

  29. CW: Spam incident analysis, long term effects of data breaches

    Here's a mind twister of a story about email #spam and security #breaches at companies of any size, and how breaches can impact you years later.

    In 2017, I bought a T-shirt to support the #Defcon #CryptoPrivacyVillage from #Teespring. To complete the order, I created an account on Teespring's website.

    Years later, in January, 2021, Teespring data was leaked to the web after an alleged breach. (zdnet.com/article/hacker-leaks). The company did not notify me of the breach or trigger a password reset, or anything. I haven't logged in to their website since I ordered the shirt.

    Flash forward to today. I just received an email sent using a service from #Intuit that gives vendors an option to send invoices to customers.

    All of the information in the email is forged, and the message somehow only got to me because the spammers contrived a way to forge the email address in such a way that what appears in the To: header in the email is different from where it was sent, an address *that is only visible in the full message headers in the message source*

    What you'll see is that the message actually came to my registered email address (teespring@ [a domain I own]) but the To: header shows a contrived email address from a domain I've never heard of. I wasn't BCCed here. This is something new, and I suspect that this method of #spoofing is facilitated through Intuit's invoicing feature.

    In any case, it's a good reminder that data leaked in breaches can have long-lasting consequences, up to and including the use by #malspam to try to infect your computer or by #phishing or #scammers who try to get you to reveal sensitive information. And these effects can happen years later.

    It's also a good place to tease out that my technique for discovering breaches of this type is to have registered a personal domain name, and use a wildcard email inbox that allows me to use a different "address" for each site I wish to register with. This method gives the the ability to quickly identify the company or organization whose data was leaked to spammers.

    Stay safe out there. The night is dark and full of scam artists.

  30. CW: Spam incident analysis, long term effects of data breaches

    Here's a mind twister of a story about email #spam and security #breaches at companies of any size, and how breaches can impact you years later.

    In 2017, I bought a T-shirt to support the #Defcon #CryptoPrivacyVillage from #Teespring. To complete the order, I created an account on Teespring's website.

    Years later, in January, 2021, Teespring data was leaked to the web after an alleged breach. (zdnet.com/article/hacker-leaks). The company did not notify me of the breach or trigger a password reset, or anything. I haven't logged in to their website since I ordered the shirt.

    Flash forward to today. I just received an email sent using a service from #Intuit that gives vendors an option to send invoices to customers.

    All of the information in the email is forged, and the message somehow only got to me because the spammers contrived a way to forge the email address in such a way that what appears in the To: header in the email is different from where it was sent, an address *that is only visible in the full message headers in the message source*

    What you'll see is that the message actually came to my registered email address (teespring@ [a domain I own]) but the To: header shows a contrived email address from a domain I've never heard of. I wasn't BCCed here. This is something new, and I suspect that this method of #spoofing is facilitated through Intuit's invoicing feature.

    In any case, it's a good reminder that data leaked in breaches can have long-lasting consequences, up to and including the use by #malspam to try to infect your computer or by #phishing or #scammers who try to get you to reveal sensitive information. And these effects can happen years later.

    It's also a good place to tease out that my technique for discovering breaches of this type is to have registered a personal domain name, and use a wildcard email inbox that allows me to use a different "address" for each site I wish to register with. This method gives the the ability to quickly identify the company or organization whose data was leaked to spammers.

    Stay safe out there. The night is dark and full of scam artists.