‘Many Organizations Still Lack Cybersecurity Measures to Protect Distributed Workforce’ - Infoblox Q4 2020 Cyberthreat Intelligence Report
Summary
They have also expanded their use of software as a service (SaaS) to meet enterprise application requirements, resulting in a broad distribution of sensitive information across a variety of cloud platforms. The goal is often to steal sensitive information such as authentication data, install malware or obtain other financial credentials such as credit card numbers. The emails in this campaign carried malicious Microsoft Office documents that required the user to enable macros to execute the Remcos payload. The CIU previously reported on a Remcos campaign in July 2019 that distributed Rich Text Format (RTF) files and exploited the Microsoft Equation Editor remote code execution vulnerability. The CIU has previously written several reports on LokiBot, including on campaigns that used coronavirus-themed lures, NGROK tunneling to download payloads and malicious RTF files to infect victims.