Severity
Medium
Analysis Summary
Two separate Malspam campaigns have been detected.
One of the campaigns is a Paychex Themed Malspam dropping the Trickbot malware.
The other one is a Swift themed malicious Loki-ISO Malspam campaign.
Email subjects have been retrieved and given below.
Impact
Trickbot
Loki-ISO
Indicators of Compromise
| Email Subject | Payment Swift Copy FYR RE: Tax verification documents |
Remediation
Scan for the given email subjects. If found, block the sender’s IP, Email Address etc.