logo

Suspected Phishing Campaign Targeting Finance Team with Invoice Lures

ID: 34ea58d6-e59c-47b5-a4c5-7a10fab62ab9

STIX ID: report--34ea58d6-e59c-47b5-a4c5-7a10fab62ab9

Threat Score

70/100

Uploaded: 2026-04-13

Created by: Report Uploader

TLP:GREEN
...
...
On 12 April 2026 a spearphishing campaign targeted a mid-sized manufacturer's finance department with a macro-enabled Excel file (Invoice_April_2026.xlsm) from a spoofed supplier address; enabling macros launched a PowerShell command that downloaded a second-stage payload (http://185.199.110.153/update/office365.bin), which subsequently connected to a C2 (45.77.12.44), established persistence via HKCU\Software\Microsoft\Windows\CurrentVersion\Run\OfficeSync, and was assessed as financially motivated to steal credentials and deploy additional malware (SHA256: 8c4a9d7d0b2e31f10ff4f6c1cb6af8d8b74ec9a320f8a3fb2f74396b8d92fa11).