Threat Advisory

North American Transportation Companies Targeted by Lumma Stealer and NetSupport Malware

Threat: Malware
Targeted Region: North America
Targeted Sector: Critical Infrastructure
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A cluster of malicious activity is currently targeting transportation and logistics companies in North America, employing compromised legitimate email accounts to deliver various malware payloads. This approach involves injecting malicious content into ongoing email conversations, making the messages appear authentic. The exact method by which the threat actor gains access to these accounts remains unclear, but at least 15 compromised accounts have been identified in the ongoing campaigns.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A cluster of malicious activity is currently targeting transportation and logistics companies in North America, employing compromised legitimate email accounts to deliver various malware payloads. This approach involves injecting malicious content into ongoing email conversations, making the messages appear authentic. The exact method by which the threat actor gains access to these accounts remains unclear, but at least 15 compromised accounts have been identified in the ongoing campaigns.[emaillocker id="1283"]

The campaigns predominantly delivered Lumma Stealer, StealC, and NetSupport, shifting tactics in August to incorporate new infrastructure and additional malware such as DanaBot and Arechclient2. Common delivery methods include messages containing Google Drive URLs leading to an internet shortcut (.URL) file, or direct attachments of .URL files. Upon execution, these files leverage SMB to access executables from remote shares, facilitating malware installation. A new technique, referred to as “ClickFix,” emerged in directing users through a series of dialogue boxes to copy and execute a Base64 encoded PowerShell script, ultimately loading DanaBot via an MSI file. The use of these techniques indicates a calculated approach, as the campaigns impersonate specific logistics software to enhance credibility.

This targeted activity highlights an alarming trend among who are increasingly refining their social engineering tactics to create more convincing lures. By leveraging legitimate email accounts and impersonating familiar software, these actors raise the likelihood that unsuspecting recipients will install malware. It is crucial for members of the transportation and logistics sector, as well as general users, to remain vigilant when interacting with emails from known contacts that exhibit unusual behavior or content. Verifying the authenticity of such communications through alternative means is highly recommended to mitigate risks associated with this sophisticated threat landscape.

THREAT PROFILE:

Tactic Technique Id Technique
Initial Access T1566 Phishing
T1199 Trusted Relationship
 Execution T1204 User Execution
T1059 Command and Scripting Interpreter
Persistence T1098 Account Manipulation
Defense Evasion T1027 Obfuscated Files or Information
 Credential Access  T1003 OS Credential Dumping
Discovery T1046 Network Service Discovery
Lateral Movement  T1021 Remote Services
Collection T1056 Input Capture
 Command and Control T1071 Application Layer Protocol
 Exfiltration  T1567 Exfiltration Over Web Service
 Impact  T1485 Data Destruction

REFERENCES:

The following reports contain further technical details:
https://thehackernews.com/2024/09/transportation-companies-hit-by.html

[/emaillocker]
crossmenu