EXECUTIVE SUMMARY
A cluster of malicious activity is currently targeting transportation and logistics companies in North America, employing compromised legitimate email accounts to deliver various malware payloads. This approach involves injecting malicious content into ongoing email conversations, making the messages appear authentic. The exact method by which the threat actor gains access to these accounts remains unclear, but at least 15 compromised accounts have been identified in the ongoing campaigns.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
A cluster of malicious activity is currently targeting transportation and logistics companies in North America, employing compromised legitimate email accounts to deliver various malware payloads. This approach involves injecting malicious content into ongoing email conversations, making the messages appear authentic. The exact method by which the threat actor gains access to these accounts remains unclear, but at least 15 compromised accounts have been identified in the ongoing campaigns.[emaillocker id="1283"]
The campaigns predominantly delivered Lumma Stealer, StealC, and NetSupport, shifting tactics in August to incorporate new infrastructure and additional malware such as DanaBot and Arechclient2. Common delivery methods include messages containing Google Drive URLs leading to an internet shortcut (.URL) file, or direct attachments of .URL files. Upon execution, these files leverage SMB to access executables from remote shares, facilitating malware installation. A new technique, referred to as “ClickFix,” emerged in directing users through a series of dialogue boxes to copy and execute a Base64 encoded PowerShell script, ultimately loading DanaBot via an MSI file. The use of these techniques indicates a calculated approach, as the campaigns impersonate specific logistics software to enhance credibility.
This targeted activity highlights an alarming trend among who are increasingly refining their social engineering tactics to create more convincing lures. By leveraging legitimate email accounts and impersonating familiar software, these actors raise the likelihood that unsuspecting recipients will install malware. It is crucial for members of the transportation and logistics sector, as well as general users, to remain vigilant when interacting with emails from known contacts that exhibit unusual behavior or content. Verifying the authenticity of such communications through alternative means is highly recommended to mitigate risks associated with this sophisticated threat landscape.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1566 | Phishing |
| T1199 | Trusted Relationship | |
| Execution | T1204 | User Execution |
| T1059 | Command and Scripting Interpreter | |
| Persistence | T1098 | Account Manipulation |
| Defense Evasion | T1027 | Obfuscated Files or Information |
| Credential Access | T1003 | OS Credential Dumping |
| Discovery | T1046 | Network Service Discovery |
| Lateral Movement | T1021 | Remote Services |
| Collection | T1056 | Input Capture |
| Command and Control | T1071 | Application Layer Protocol |
| Exfiltration | T1567 | Exfiltration Over Web Service |
| Impact | T1485 | Data Destruction |
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2024/09/transportation-companies-hit-by.html