U.S. Manufacturer Most Recent Target Of Lokibot Malspam Campaign
Arthur T Knackerbracket has found the following story:
A large U.S. manufacturing company is the latest organization to be targeted with the LokiBot trojan - although this most recent campaign harbored some bizarre red flags.
The well-known LokiBot malware has popped up in several malicious spam campaigns over the past year, covertly siphoning information from victims' compromised endpoints. Researchers this week are warning of the most recent sighting of the malware, which was recently spotted in spam messages targeting a large U.S. manufacturing company.
Researchers first discovered the campaign on Aug. 21 after an unnamed U.S. semiconductor distributor received a spam email sent to the sales department from a potentially compromised "trusted" sender. The email, purporting to be distributing an attached request for quotation, was actually harboring prolific trojan LokiBot. "The attack is pretty straightforward," said Fortinet researchers in a Tuesday analysis of the attack. "The LokiBot sample has a file size of 286 KB and was recently compiled on Aug 21, which is coincidentally the same date as when the malicious spam was sent". The spam email then encourages the user to open the attachment as the senders' colleague is currently out of office, and at the same time offers the potential victim some assurance that he/she can provide further clarification of the contents within the document if needed."
Read more of this story at SoylentNews.