Spam and phishing mail

Paypal phishing in Dutch

Today our spam traps caught a phishing email targeting Paypal users that we detect proactively as Trojan-Spy.HTML.Fraud.gen.

Of course such emails normally aren’t anything special – the interesting bit about this one is that it’s in Dutch. This falls in with my prediction towards the end of last year that we’d start to see an increase in the use of Dutch (which is, after all, a minority language) in cyber scams.

A bit of searching through our archives showed that this mail was a re-run from an attack that occurred last week. This indicates that the first one was probably reasonably successful – if not, why resend the same email?

Although it’s pretty good, the Dutch is not exactly perfect. This in itself might alert users to the fact that something is not quite legitimate. And the bad guys forgot another major factor – although the email is in Dutch, the site that it links to isn’t. Hopefully this will act as a red flag so that recipients don’t enter their data on the site.

Paypal phishing in Dutch

Your email address will not be published.

 

Reports

The SessionManager IIS backdoor

In early 2022, we investigated an IIS backdoor called SessionManager. It has been used against NGOs, government, military and industrial organizations in Africa, South America, Asia, Europe, Russia and the Middle East.

APT ToddyCat

ToddyCat is a relatively new APT actor responsible for multiple sets of attacks against high-profile entities in Europe and Asia. Its main distinctive signs are two formerly unknown tools that we call ‘Samurai backdoor’ and ‘Ninja Trojan’.

WinDealer dealing on the side

We have discovered that malware dubbed WinDealer, spread by Chinese-speaking APT actor LuoYu, has an ability to perform intrusions through a man-on-the-side attack.

APT trends report Q1 2022

This is our latest summary of advanced persistent threat (APT) activity, focusing on events that we observed during Q1 2022.

Subscribe to our weekly e-mails

The hottest research right in your inbox