Zip attachment in the message contains a doc file. This, if opened, contacts a link from an internal list and downloads dll from Epoch botnets 1 and 3, which initiates malware infection.
New messages with compressed attachment, which contains a .doc file. This, if opened, contacts a link from an internal list that downloads the malware from the Epoch 2 botnet.
The bait is always real stolen email conversations. The doc attachment contacts the first available url from a list within it to start the malware infection.
Cryptolaemus cyber security experts find new links in the botnet that download the malware. The continuous evolution of the worldwide campaign confirms that it will continue.