2022-05-18

Phishing with World Health Organization Themes

Level: 
Tactical
  |  Source: 
ProofPoint
Information & Technology
Share:

Phishing with World Health Organization Themes

Research from ProofPoint has identified the distribution of Nerbian remote access trojan (RAT), through phishing emails using COVID-19 and World Health Organization themes. The threat campaign was traced back to getting its start April 26th, 2022, with emails targeting entities located in Italy, Spain, and the United Kingdom. Emails delivered contain either a malicious document or a compressed archive containing a malicious document. The process flow upon the execution of the embedded macro is, CMD calls PowerShell to download a BAT file, the BAT file launches the PowerShell to download additional payloads including the malicious RAT. The RAT establishes persistence and has the capabilities to download additional payloads as needed. There is currently no attribution placed on the Nerbian RAT.

Get trending threats published weekly by the Anvilogic team.

Sign Up Now