LausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th)

Summary

A malspam message impersonating a legitimate company employee was detected in a mail gateway quarantine. The message contained malicious content in an attachment and failed SPF and DMARC checks, preventing it from reaching the recipient.

IFF Assessment

FOE

The article describes a malspam campaign utilizing social engineering and technical evasion tactics, which poses a threat to defenders.

Defender Context

This analysis highlights a common malspam technique involving impersonation and malicious attachments. Defenders should be vigilant about social engineering tactics and ensure robust email filtering, including SPF and DMARC checks, to mitigate such threats.

Read Full Story →