#malspam — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #malspam, aggregated by home.social.
-
Over the past days, active #malspam campaigns targeting LatAm users 🇦🇷🇧🇷🇲🇽 have been delivering the Grandoreiro banking trojan 🏦💰
📧 Email ➔ 📜 JS file ➔ 📑 Fake PDF download
Final payload is hosted on MediaFire 🔥 free file hosting
C2 network traffic is rather trivial to detect as #Grandoreiro is using Embarcadero Delphi compilation tools' HTTP user agent 🖥️⤵️
User-Agent: Embarcadero URI Client/1.0
🔎 Botnet C2 domain resolved via Google DNS-over-HTTPS (DoH): devilmaycry.servehumour .com 👀
📡 Grandoreiro botnet C2s hosted at AWS:
54.80.154.193
54.91.129.132
54.91.223.28🌐 Payloads URLs:
https://urlhaus.abuse.ch/browse/tag/Grandoreiro/📄 Malware samples:
https://bazaar.abuse.ch/browse/signature/Grandoreiro/🦊 Relevant IOCs are available on ThreatFox:
https://threatfox.abuse.ch/browse/malware/win.grandoreiro/ -
Over the past days, active #malspam campaigns targeting LatAm users 🇦🇷🇧🇷🇲🇽 have been delivering the Grandoreiro banking trojan 🏦💰
📧 Email ➔ 📜 JS file ➔ 📑 Fake PDF download
Final payload is hosted on MediaFire 🔥 free file hosting
C2 network traffic is rather trivial to detect as #Grandoreiro is using Embarcadero Delphi compilation tools' HTTP user agent 🖥️⤵️
User-Agent: Embarcadero URI Client/1.0
🔎 Botnet C2 domain resolved via Google DNS-over-HTTPS (DoH): devilmaycry.servehumour .com 👀
📡 Grandoreiro botnet C2s hosted at AWS:
54.80.154.193
54.91.129.132
54.91.223.28🌐 Payloads URLs:
https://urlhaus.abuse.ch/browse/tag/Grandoreiro/📄 Malware samples:
https://bazaar.abuse.ch/browse/signature/Grandoreiro/🦊 Relevant IOCs are available on ThreatFox:
https://threatfox.abuse.ch/browse/malware/win.grandoreiro/ -
PSA: If you're seeing links that literally start with _wildcard_ in #malspam, these are dropping #screenconnect (usual relay c2) via #zoom update lure.
1f7ab5418d489fdd2fb392ada3accc77c13586f94f059ee8e5cc83c0974b614b
-
PSA: If you're seeing links that literally start with _wildcard_ in #malspam, these are dropping #screenconnect (usual relay c2) via #zoom update lure.
1f7ab5418d489fdd2fb392ada3accc77c13586f94f059ee8e5cc83c0974b614b
-
A csv formatted list of #malspam campaigns that crossed my path in July to include #malware type, subjects, c2's, hashes, and email exfil addresses:
https://gist.github.com/silence-is-best/48b613e82bf64f1fd8b9a231ccdd590b
-
A csv formatted list of #malspam campaigns that crossed my path in June to include #malware type, c2, hash, subject, and email exfil addresses:
https://gist.github.com/silence-is-best/247bf72a24c316a9d4c9bedc62df2ea0
-
A csv formatted list of #malspam campaigns that crossed my path in June to include #malware type, c2, hash, subject, and email exfil addresses:
https://gist.github.com/silence-is-best/247bf72a24c316a9d4c9bedc62df2ea0
-
A csv formatted list of #malspam campaigns that crossed my path in May to include #malware, subjects, hashes, c2's, and email exfil addresses:
https://gist.github.com/silence-is-best/9b7365532f5ceb3b963bbc2dc3d8e876
-
A csv formatted list of #malspam campaigns that crossed my path in May to include #malware, subjects, hashes, c2's, and email exfil addresses:
https://gist.github.com/silence-is-best/9b7365532f5ceb3b963bbc2dc3d8e876
-
An on time (yay) csv formatted list of #malspam campaigns that crossed my path in April to include #malware type, c2, hash, subject, and email exfil addresses:
https://gist.github.com/silence-is-best/bc95a949f272f8c5487d057bbd74d14f
-
An on time (yay) csv formatted list of #malspam campaigns that crossed my path in April to include #malware type, c2, hash, subject, and email exfil addresses:
https://gist.github.com/silence-is-best/bc95a949f272f8c5487d057bbd74d14f
-
When your #malspam threat actor forgets to properly configure their #remcos ....ya "Juniorer" indeed 🤣
https://app.any.run/tasks/1ff77354-94ca-4d30-b6f7-a86aff32e1af
-
When your #malspam threat actor forgets to properly configure their #remcos ....ya "Juniorer" indeed 🤣
https://app.any.run/tasks/1ff77354-94ca-4d30-b6f7-a86aff32e1af
-
Trust this “Amazon” phishing email in Japan—and you’re Prime sashimi 🎣 🍣
Looking into our malspam data, we identified an active campaign impersonating Amazon and targeting Japanese citizens. The emails use subjects such as 「至急 Amazonプライム会員情報の確認」 (“Urgent: Confirm Amazon Prime member information”).
The URLs within the emails ultimately lead to an Amazon phishing page, but only after routing victims through a TDS. Interestingly, instead of keeping the TDS step invisible, the actors chose to show it off—repackaging it as a reassuring security check.
Upon clicking the link within the email, victims are first redirected to an RDGA TDS domain, where fingerprinting occurs. If the user does not match the targeting criteria (e.g., connecting from outside Japan), access is blocked. If they do match, potential victims are redirected to a second RDGA domain.
This second and last domain is not a TDS domain, but funny enough, these actors decided they would emulate it anyway!At that step victims are already at the landing page but instead of immediately displaying a standard Amazon phishing page, the website displays a CAPTCHA and fake console interface simulating environment fingerprinting checks to “make sure your environment and connection is safe” before "proceeding to the landing page". Ironically, part of their message is true: fingerprinting did happen one domain earlier. It just wasn’t for the user’s benefit—it was to make sure the environment was safe… for the scammers. A few seconds later, without added user interaction needed, a fake Amazon login page is displayed.
Domains samples:
qqc10c[.]cyou
51wang11c[.]cyou#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #phishing #amazon #malspam #email #fingerprinting #japan
-
Trust this “Amazon” phishing email in Japan—and you’re Prime sashimi 🎣 🍣
Looking into our malspam data, we identified an active campaign impersonating Amazon and targeting Japanese citizens. The emails use subjects such as 「至急 Amazonプライム会員情報の確認」 (“Urgent: Confirm Amazon Prime member information”).
The URLs within the emails ultimately lead to an Amazon phishing page, but only after routing victims through a TDS. Interestingly, instead of keeping the TDS step invisible, the actors chose to show it off—repackaging it as a reassuring security check.
Upon clicking the link within the email, victims are first redirected to an RDGA TDS domain, where fingerprinting occurs. If the user does not match the targeting criteria (e.g., connecting from outside Japan), access is blocked. If they do match, potential victims are redirected to a second RDGA domain.
This second and last domain is not a TDS domain, but funny enough, these actors decided they would emulate it anyway!At that step victims are already at the landing page but instead of immediately displaying a standard Amazon phishing page, the website displays a CAPTCHA and fake console interface simulating environment fingerprinting checks to “make sure your environment and connection is safe” before "proceeding to the landing page". Ironically, part of their message is true: fingerprinting did happen one domain earlier. It just wasn’t for the user’s benefit—it was to make sure the environment was safe… for the scammers. A few seconds later, without added user interaction needed, a fake Amazon login page is displayed.
Domains samples:
qqc10c[.]cyou
51wang11c[.]cyou#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #phishing #amazon #malspam #email #fingerprinting #japan
-
A very late (due to work travel) csv formatted list of #malspam campaigns that crossed my path in March to include #malware type, subject, hash, c2, and email exfil addresses:
https://gist.github.com/silence-is-best/440abd3e683adf69f531371cf56cd338
-
A very late (due to work travel) csv formatted list of #malspam campaigns that crossed my path in March to include #malware type, subject, hash, c2, and email exfil addresses:
https://gist.github.com/silence-is-best/440abd3e683adf69f531371cf56cd338
-
A csv formatted list of #malspam campaigns that crossed my path in February to include subjects, #malware type, hashes, c2's, and email exfil addresses:
https://gist.github.com/silence-is-best/49cbc51145478ed68d06e02e14ddc135
-
New 2026 telemetry from Bitdefender indicates 41% of Valentine’s-themed email traffic contained scam elements.
Threat vectors observed:
• Brand impersonation campaigns
• AI-generated dating personas
• Advance-fee survey funnels
• Delivery notification phishing
• Pharma spam distribution
• Healthcare provider impersonation (e.g., Techniker Krankenkasse)
Geographic targeting concentrated in the U.S. (55%) and key European markets.Question for defenders:
Are current email filtering models sufficiently adaptive to seasonal emotional triggers amplified by generative AI?
Engage below.Follow @technadu for threat intelligence reporting.
#ThreatIntel #Phishing #EmailSecurity #AIThreats #SOC #BlueTeam #FraudDetection #BrandAbuse #SecurityResearch #CyberDefense #Malspam #DigitalRisk
-
A csv formatted list of #malspam campaigns that crossed my path in January to include #malware, c2, hash, subject, and some email exfil addresses:
https://gist.github.com/silence-is-best/8b91cfa90b598f71dbd7169f0391c98c
-
A csv formatted list of #malspam campaigns that crossed my path in January to include #malware, c2, hash, subject, and some email exfil addresses:
https://gist.github.com/silence-is-best/8b91cfa90b598f71dbd7169f0391c98c
-
If you've been experiencing these new #malspam with @Action1corp #action1 RMM, there's a tasty lil file called C:\Windows\Action1\what_is_this.txt that's everything you need to know:
https://app.any.run/tasks/a38ca435-f03f-4e77-aac0-f7446b6fe4df -
A short (and late due to vacation) csv formatted list of #malspam campaigns that crossed my path in December to include #malware type, subject, hash, c2, and email exfil addresses:
https://gist.github.com/silence-is-best/720a513ff366780662870bc0dd080ce3
-
Happy Cyber(crime) Monday. Someone is sending out these bogus "e-signature" notifications as #malspam.
They lead to a page on Google Drive that has an interstitial link. When you click it, the page pushes an installer for N-Able Advanced Monitoring Agent, a commercial IT remote management tool. https://www.virustotal.com/gui/file/5ddcff44de366e6693c24e189121011ba664d6e71686e9463bb1574572564909/detection
This is just the latest evolution of the attack I documented on the @Netcraft blog before the holiday break: https://www.netcraft.com/blog/shared-document-spam-delivers-remote-access-tool #spam #malware #RAT
-
Happy Cyber(crime) Monday. Someone is sending out these bogus "e-signature" notifications as #malspam.
They lead to a page on Google Drive that has an interstitial link. When you click it, the page pushes an installer for N-Able Advanced Monitoring Agent, a commercial IT remote management tool. https://www.virustotal.com/gui/file/5ddcff44de366e6693c24e189121011ba664d6e71686e9463bb1574572564909/detection
This is just the latest evolution of the attack I documented on the @Netcraft blog before the holiday break: https://www.netcraft.com/blog/shared-document-spam-delivers-remote-access-tool #spam #malware #RAT
-
A csv formatted list of #malspam campaigns that crossed my path in November to include #malware type, c2, hash, subject, and some email exfil addresses:
https://gist.github.com/silence-is-best/b0eed8c8a6d6f6381a30d17047603726
-
A csv formatted list of #malspam campaigns that crossed my path in October to include subject, hash, #malware type, c2's, and email exfil addresses:
https://gist.github.com/silence-is-best/5ac67205cb12c0244d0c591b95dde1c9
-
An embarrassingly small csv formatted list of #malspam campaigns that crossed my path in September to include hash, subject, c2, #malware type and email exfil addresses:
https://gist.github.com/silence-is-best/d88941f83dc233ae953fd62daa34ab88
-
A sparse and late (due to holiday and <groan> jury duty) csv formatted list of #malspam campaigns that crossed my path in August to include subjects, hashes, c2, #malware type, and email exfil addresses:
https://gist.github.com/silence-is-best/fe83da37dd3067acd817b21b85eb2692
-
-
A semi-late (due to Friday off) csv formatted list of #malspam campaigns that crossed my path in July to include #malware, hash, c2, subjects, and email exfil addresses:
https://gist.github.com/silence-is-best/a2b497e7cf1d6998045ed00f35ac43ac
-
A semi-late (due to illness, nothing major) csv formatted list of #malspam campaigns that crossed my path in June to include subjects, #malware type, hashes, c2's, and email exfil addresses:
https://gist.github.com/silence-is-best/44d48000436c26511a31b6ff331212b0
-
A (sparse) csv formatted list of #malspam campaigns that crossed my path in May to include #malware, subject, hashes, c2, and email exfil addresses.
https://gist.github.com/silence-is-best/ede4c444ba406003642a99017274413d
-
A csv formatted list of #malspam campaigns that crossed my path in April to include #malware type, c2, hash, subject, and email exfill addresses:
https://gist.github.com/silence-is-best/413e27ccb3b5dfe3d2260b94968d8c73
-
2025-04-17 (Thursday): I found an example of #MassLogger malware sent through #malspam. The infection traffic indicates stolen data sent to a mail server at mail.bouttases[.]fr.
Details at https://github.com/malware-traffic/indicators/blob/main/2025-04-17-IOCs-for-MassLogger-infection.txt
-
2025-04-17 (Thursday): I found an example of #MassLogger malware sent through #malspam. The infection traffic indicates stolen data sent to a mail server at mail.bouttases[.]fr.
Details at https://github.com/malware-traffic/indicators/blob/main/2025-04-17-IOCs-for-MassLogger-infection.txt
-
Last week I posted a thread about a #spam campaign delivering a #ConnectWise client as its payload. As of this morning, the threat actors have changed the payload (https://www.virustotal.com/gui/file/30e1d059262b851a2b432ec856aeba5bb639ba764aa85643703163d62000a2f4) and it appears to try to connect to the address "relay.noscreener[.]info" which resolves to 104.194.145.66.
Embedded in the installer .msi file is a file called system.config, which contains this domain name and a base64-encoded string.
The fake Social Security website is still being hosted on a compromised site that belongs to a temp agency based on the east coast of the US.
Previous thread:
-
Last week I posted a thread about a #spam campaign delivering a #ConnectWise client as its payload. As of this morning, the threat actors have changed the payload (https://www.virustotal.com/gui/file/30e1d059262b851a2b432ec856aeba5bb639ba764aa85643703163d62000a2f4) and it appears to try to connect to the address "relay.noscreener[.]info" which resolves to 104.194.145.66.
Embedded in the installer .msi file is a file called system.config, which contains this domain name and a base64-encoded string.
The fake Social Security website is still being hosted on a compromised site that belongs to a temp agency based on the east coast of the US.
Previous thread:
-
However, because this attack has been going on for two weeks, some endpoint protection tools (well, about a third of them) are catching on that this particular file is bad, and should feel bad.
https://www.virustotal.com/gui/file/13d71b884a0625f3aa3805fb779d95513d0485671ab8c090a0c790ceda071e63
The most important lesson here is that attackers always come up with new ways to evade detection. Using a commercially available, normally legitimate remote access tool with a valid cryptographic signature lets the attacker bypass some kinds of endpoint detection.
Remember to check the From: address in emails, and the destination of any links they point to. You can do this by hovering your mouse over the link without clicking, and waiting a second. If it says it's from the SSA, but it isn't pointing to SSA.gov, then it's a lie.
If you find content like this useful, please follow me here, or on LinkedIn: https://www.linkedin.com/in/andrew-brandt-9603682/
9/fin
-
However, because this attack has been going on for two weeks, some endpoint protection tools (well, about a third of them) are catching on that this particular file is bad, and should feel bad.
https://www.virustotal.com/gui/file/13d71b884a0625f3aa3805fb779d95513d0485671ab8c090a0c790ceda071e63
The most important lesson here is that attackers always come up with new ways to evade detection. Using a commercially available, normally legitimate remote access tool with a valid cryptographic signature lets the attacker bypass some kinds of endpoint detection.
Remember to check the From: address in emails, and the destination of any links they point to. You can do this by hovering your mouse over the link without clicking, and waiting a second. If it says it's from the SSA, but it isn't pointing to SSA.gov, then it's a lie.
If you find content like this useful, please follow me here, or on LinkedIn: https://www.linkedin.com/in/andrew-brandt-9603682/
9/fin
-
When clicked, the button delivers malware, but it's an unexpected payload: A client installer for the commercial remote-access tool ConnectWise.
Every time I clicked the download link, it gave me the same file with six different random digits appended to the filename. Note that it is not, as the website implies, a PDF document, but a Windows executable file, with a .exe extension.
8/
-
This is where I tell you: don't do this! I am a trained professional. I click all the bad links so you don't have to. I am going to show you what happens next.
A button appears on this page, labeled "Access Your Statement." The site serving up this payload delivers a file named "Social Security Statement Documents [six digit random number].exe"
7/
-
Finally the target lands on a page on the InMotion site that closely resembles the look-and-feel of the content in the email message.
The page tells the visitor, in part "Download your statement as a PDF file" and "For security reasons, we recommend accessing your statement through your secure device."
Spoiler alert: It was not a PDF file.
(Edit: A reader informs me that this appears to be the hosting space used by the temp agency website, and that for whatever reason, the URL appears differently here.)
6/
-
The target's browser then lands on another website, hosted by a large hosting service, InMotion Hosting. As with the temp agency website, the attackers have set up multiple URLs on this site, where the first URL performs a 302 redirect to go to the second URL, for no apparent reason other than to create the URL equivalent of a Rube Goldberg contraption.
5/
-
That link then immediately 302 redirects the target's browser to a link on a second website, one that belongs to a temp agency based in the US state of Maryland.
The attackers have created two URLs on this company's site for this purpose. The first one redirects to the second one.
Again, the site appears to have been compromised and used specifically for the purpose of obfuscating the redirection chain.
4/
-
The first 302 redirect points to a page on a website belonging to a small business that has, apparently, been compromised and abused for this purpose.
3/
-
In this attack, the spammers have been sending emails that look like this official-appearing notification from the Social Security Administration.
The message says "Your Social Security Statement is ready to review" and includes a button at the bottom labeled "Download Statement."
The button links to a shortened URL that uses the link-shortening service t.ly to lead the target to a chain of 302 redirects. Malware spammers often do this to fool web reputation services and obfuscate the final destination of the link.
2/
-
It sometimes pays to run domains that serve purely as spam honeypots. Case in point: A spammer has been delivering a ConnectWise commercial remote access client application as a payload in a scam that uses the purported arrival of a US Social Security statement as its hook.
A 🧵 ...
#ConnectWise #malware #spam #malspam #attacksurface #SocialSecurity #SocialSecurityAdministration #SSA #usgov
-
Malspam Monday is when I check the inboxes of my honey pot accounts for anything interesting distributed through email.
Today, I found an example of #GuLoader for #Remcos #RAT
Details at https://github.com/malware-traffic/indicators/blob/main/2025-03-24-GuLoader-for-Remcos-RAT.txt
-
⚠️ Uwaga na e-maile z kancelarii prawnych
Na skrzynki Polaków znów trafiają pisma, w których oszuści podszywają się pod różne znane kancelarie prawne. Wiadomości informują o naruszeniu praw autorskich i wyglądają profesjonalnie. Zawierają też link do skanu pisma z “dowodami naruszeń praw autorskich”.
I to właśnie kliknięcie na ten link, pobranie oraz uruchomienie podlinkowanych plików może spowodować infekcję komputera złośliwym oprogramowaniem oraz — w konsekwencji — kradzież danych oraz stratę kont w serwisach społecznościowych. Na atak powinni uważać zwłaszcza posiadacze kont na Facebooku.
Po czym rozpoznać, że to oszustwo? E-maile są wysyłane z różnych adresów w domenie GMail. Link do pisma z dowodami, wbrew opisowi, nie prowadzi do PDF. I na marginesie — choć otrzymanie wiadomości o naruszeniu praw autorskich może wywołać stres, to warto mieć świadomość, że poważna korespondencja z kancelarii prawnych, jeśli ma być wiążąca, powinna dotrzeć do nas w formie papierowej.
Otrzymałem taką wiadomość — co robić, jak żyć?Jeśli otrzymałeś taką wiadomość, nic nie musisz robić. Możesz ją zignorować. Żadne Twoje dane nie wyciekły, a żadna z opublikowanych przez Ciebie treści nie naruszyła praw autorskich innych firm.
Jeśli tylko pobrałeś załącznik — nie zostałeś zainfekowany.
Jeśli pobrałeś załącznik, rozpakowałeś go i uruchomiłeś aplikację z załącznika, to jak najszybciej poddaj swój komputer analizie pod kątem złośliwego oprogramowania z innego urządzenia zaloguj się na wszystkie istotne konta oraz zmień na nich hasła, a tam gdzie to możliwe, wyloguj również “pozostałe sesje/urządzenia”.To ostrzeżenie wysłaliśmy także jako alert do użytkowników naszej bezpłatnej aplikacji CyberAlerty. Jeśli też chcesz być informowany o atakach, [...]
#Cyberalert #Malspam #PrawaAutorskie #SpearPhishing
https://niebezpiecznik.pl/post/uwaga-na-e-maile-z-kancelarii-prawnych/