
10/6/2020 · Elaine Dzuba
What this post added
This post details a sophisticated phishing campaign leveraging stolen Political Action Committee (PAC) email content and compromised legitimate email accounts to deliver the Emotet banking trojan. The campaign bypasses traditional security by using valid DMARC, DKIM, and SPF records, and employs techniques like display name spoofing. The malware delivery mechanism involves a Microsoft Word document with VBA macros that execute obfuscated PowerShell commands to download Emotet from compromised WordPress sites. Indicators of compromise include specific compromised sender email addresses, IP addresses, domains, Emotet websites, attachment hashes, file names, and PowerShell executable names.