skip to Main Content

Cybercrime: phishing campaign carries OriginBotnet, RedLine Clipper and AgentTesla

A phishing campaign carries OriginBotnet, RedLine Clipper and AgentTesla. Fortinet cybersecurity experts: A word points to a link that downloads the loader. This then installs and executes the three malware

A phishing campaign is conveying a malicious doc document, which downloads a loader. This distributes OriginBotnet, RedLine Clipper and AgentTesla. Fortinet cybersecurity researchers discovered this. The attached Word file has a blurry image and a spoofed reCAPTCHA. Objective: to make the victim open the document and, consequently, activate a link that downloads the loader. This then links to a further URL to download and execute the three malware.

Back To Top