Even emails from colleagues can be dangerous: Fraudsters have found new ways to distribute malware

18:19    26 August, 2024

Cybercriminals have developed a new scheme for distributing malware and collecting data: now they disguise phishing emails as responses to supposedly previously sent messages and ask the victim to forward the received email to a colleague, exploiting the trust between employees.

As TASS reports with reference to Positive Technologies (PT), this scheme was used by the Hive0117 group, which has previously been noticed in similar attacks. In the emails, the fraudsters attach a password-protected archive with the DarkWatchman Trojan. This malware allows you to remotely connect to a computer, download other programs, collect data about the company and spread across the network.

To increase trust, the attackers design the message as a response to the previous email and create a sense of urgency, for example, by mentioning a tax audit and asking to forward the information to the accountant. Experts note that such attacks are often successful, since employees tend to trust their colleagues. One such incident was recently recorded at a major holding company.

According to Positive Technologies, malware remains the most common method of attacking companies, accounting for 64% of all incidents, and for the second quarter in a row, there has been an increase in attacks using remote control software.



© NEWS.am Medicine