Watch out TA866 brings WasabiSeed & Screenshotter Malware, invoice phishing

January 21, 2024
1 min read

TLDR: The threat actor TA866 has launched a new phishing campaign targeting North America, deploying known malware families including WasabiSeed and Screenshotter. The campaign involves sending thousands of invoice-themed emails containing decoy PDF files that, if clicked, lead to a multi-step infection chain resulting in the delivery of the malware payload. TA866, which was first documented in February 2023, is believed to be financially motivated. The campaign marks the return of the actor after a nine-month hiatus and closely resembles previous campaigns attributed to TA866. The latest attack chain primarily involves the use of PDFs with rogue OneDrive links, distributed using a spam service provided by TA571. The malware delivered in this campaign includes DarkGate, a Malware-as-a-Service tool sold on underground forums. The resurgence of TA866 follows the discovery of a new evasion tactic that misuses the caching mechanism of security products.

Latest from Blog

Bridging the cyber talent gap: tips for CISOs

TLDR: – Global cyber threats have increased twofold in recent years, leading to a talent gap of nearly 4 million cyber professionals worldwide. – Existing cyber staff are under strain, with vacancies

North Korean hackers pivot to ransomware attacks

TLDR: North Korean hackers from APT45 have shifted from cyber espionage to ransomware attacks APT45 has targeted critical infrastructure and is linked to ransomware families SHATTEREDGLASS and Maui A North Korea-linked threat

Cyber insurance evolves to cover all your online needs

TLDR: Cyber insurance coverage is evolving to help raise security baselines across businesses. Only one-quarter of companies have a standalone cyber insurance policy. In today’s evolving cybersecurity landscape, cyber insurance coverage is