Cybercrime, new email about an RFQ conveyed by Remcos via ModiloaderThe compressed attachment contains an exe file: the loader, which contacts a url and downloads… Cybercrime, new email about an RFQ conveyed by Remcos via Modiloader26 May 2023Francesco BussolettiCyber, Defence and Security The compressed attachment contains an exe file: the loader, which contacts a url and downloads the final malware.
Cybercrime, the “Hesap hareketleriniz” email carries RemcosA new zipped attachment contains an exe: the malware, while the text and C2s do… Cybercrime, the “Hesap hareketleriniz” email carries Remcos6 April 2023Francesco BussolettiDefence and Security, Restricted Area A new zipped attachment contains an exe: the malware, while the text and C2s do not change from previous campaign waves.
Cybercrime, the Remcos bank-themed campaign changes templateThe email, referring to an account statement of Garanti BBVA, now also contains an IBAN.… Cybercrime, the Remcos bank-themed campaign changes template22 February 2023Francesco BussolettiCyber, Defence and Security The email, referring to an account statement of Garanti BBVA, now also contains an IBAN. The attachment is a compressed file in z format with an exe inside: the malware.
Cybercrime, Remcos campaign via DBatLoader/ModiloaderThe xz attachment contains an exe: the loader, which contacts a url and downloads the… Cybercrime, Remcos campaign via DBatLoader/Modiloader20 February 2023Francesco BussolettiCyber, Defence and Security The xz attachment contains an exe: the loader, which contacts a url and downloads the final malware.
Cybercrime, Remcos arrives from Turkey via false account statementThe email rar attachment contains an exe file: the malware. Cybercrime, Remcos arrives from Turkey via false account statement17 February 2023Francesco BussolettiCyber, Defence and Security The email rar attachment contains an exe file: the malware.
Cybercrime, the email “Request Quotation PO.230029” conveys Vjw0rmThe js in the rar attachment contacts a url to download and run an exe:… Cybercrime, the email “Request Quotation PO.230029” conveys Vjw0rm16 February 2023Francesco BussolettiCyber, Defence and Security The js in the rar attachment contacts a url to download and run an exe: the malware. The mail provider is the same as yesterday's Remcos campaign.
Cybercrime, Remcos “YOUR INQUIRY” campaign from ChinaThe message z attachment contains an exe file: the malware. Cybercrime, Remcos “YOUR INQUIRY” campaign from China15 February 2023Francesco BussolettiCyber, Defence and Security The message z attachment contains an exe file: the malware.
Cybercrime, RemcosRat is hiding in a draft contractThe r17 attachment of the email with the subject "O/N O/186/1902" contains an exe file:… Cybercrime, RemcosRat is hiding in a draft contract9 February 2023Francesco BussolettiCyber, Defence and Security The r17 attachment of the email with the subject "O/N O/186/1902" contains an exe file: the malware.
Cybercrime, RemcosRat goes from industrial enginesThe exe attachment of the email from a French spare parts company is the malware. Cybercrime, RemcosRat goes from industrial engines6 February 2023Francesco BussolettiDefence and Security, Restricted Area The exe attachment of the email from a French spare parts company is the malware.
Cybercrime, Remcos campaign via DBatLoaderThe rar attachment contains an exe: the loader, which contacts a url and downloads the… Cybercrime, Remcos campaign via DBatLoader12 January 2023Francesco BussolettiCyber, Defence and Security The rar attachment contains an exe: the loader, which contacts a url and downloads the final malware.