216.73.217.22

Fake Social Security Statement emails trick users into installing remote tool

· Published 01/05/2025 08:36 · Modified 01/05/2025 20:26

Export JSON

Essential information

Published
01/05/2025 08:36
Modified
01/05/2025 20:26
Tags
2025-05-01 financial fraud phishing remote access tool screenconnect social engineering social security administration
Related entities
1 intrusion sets (apt), 5 techniques (mitre), 3 others

Description

A campaign is targeting users with fake emails purportedly from the US . These emails aim to trick recipients into installing , a legitimate that can be misused by cybercriminals. The campaign, attributed to a group called Molatori, sends emails with links to download the client under misleading names. Once installed, attackers can remotely access the victim's computer, potentially leading to data theft and . The campaign is difficult to detect due to the use of compromised WordPress sites for sending emails, image-based content to evade filters, and the legitimacy of the application itself.

External references