Website Security & Threat Management
PAC spoof drops Emotet: phishing campaign leverages stolen PAC content to drop Emotet

PAC spoof drops Emotet: phishing campaign leverages stolen PAC content to drop Emotet

10/6/2020 · Elaine Dzuba

What this post added

This post details a sophisticated phishing campaign leveraging stolen Political Action Committee (PAC) email content and compromised legitimate email accounts to deliver the Emotet banking trojan. The campaign bypasses traditional security by using valid DMARC, DKIM, and SPF records, and employs techniques like display name spoofing. The malware delivery mechanism involves a Microsoft Word document with VBA macros that execute obfuscated PowerShell commands to download Emotet from compromised WordPress sites. Indicators of compromise include specific compromised sender email addresses, IP addresses, domains, Emotet websites, attachment hashes, file names, and PowerShell executable names.

Read the original post ↗