12 June 20, 07:49
Quote:Cyberattackers are seizing upon the 24-hour news cycle again in order to capitalize on the current zeitgeist – this time with a fake Black Lives Matter malspam campaign that distributes the TrickBot malware.
According to Swiss security firm Abuse.ch, threat actors are posing as government officials, in an effort to lure socially minded victims into clicking on a malicious attachment in an email. The messages use a grammatically challenged subject line, “Vote anonymous about Black Lives Matter,” or “Leave a review confidentially about Black Lives Matter,” and purport to contain a survey document.
https://twitter.com/abuse_ch/status/1270739166716989443
According to sample campaign documents (first obtained by Bleeping Computer), the attachment, if opened, surfaces a button urging recipients to “Enable Editing” or “Enable Content.” If clicked, the button activates malicious macros that in turn download TrickBot, in the form of a malicious library (.DLL file).
Read more: https://threatpost.com/black-lives-matte...re/156497/