216.73.216.6

Security Brief: Threat Actors Gift Holiday Lures to Threat Landscape

· Published 19/12/2024 14:41 · Modified 19/12/2024 17:38

Export JSON

Essential information

Published
19/12/2024 14:41
Modified
19/12/2024 17:38
Tags
2024-12-19 adversary-in-the-middle (aitm) credential phishing employment fraud open office xml (ooxml) qr codes remcos rat tycoon phishing-as-a-service (phaas)
Related entities
15 techniques (mitre), 1 malware, 1 others

Description

As the holiday season approaches, threat actors are exploiting people's desires for deals, jobs, and end-of-year bonuses. Researchers have observed an increase in themed content delivering malware, fraud, and campaigns. Examples include a 'Winter Holiday Promotion' campaign delivering , campaigns impersonating HR departments to steal login information, and schemes targeting universities. These attacks use timely lures such as holiday promotions, bonus announcements, and seasonal job offers to manipulate victims into risky online behaviors. The campaigns employ various techniques, including compressed executables, , and specially crafted OOXML files to bypass detection and harvest user credentials.

External references