CERT-AGID Reports 182 Malicious Campaigns Affecting Italy During September 19–25

Summary
CERT-AGID analyzed 182 campaigns affecting Italy during September 19–25 and shared 1,411 IoCs with accredited organizations. Phishing, malware delivery, and credential and payment-data theft featured prominently.
Key points
- Of 182 campaigns, 142 specifically targeted Italian victims and 40 were generic campaigns that also affected Italy.
- The CERT identified 24 campaign themes; phishing impersonating the Revenue Agency for refunds appeared in 46 campaigns, while fake unpaid-fine notices appeared in 35.
- Compromised certified email (PEC) accounts were used to distribute MintsLoader to other PEC addresses; attackers also used domain generation algorithms.
- A fake ACI vehicle-tax payment site sought victims’ personal, vehicle, address, and payment-card details.
- A fake National Health Service page delivered different malware to Android or Windows devices based on the visitor’s User-Agent.
- Fourteen malware families were observed, including AgentTesla, AsyncRAT, BingoMod, Remcos, XWorm, and MintsLoader; delivery methods included malicious attachments, archives, scripts, and SMS links.
Article Details
- Publisher
- CERT-AGID
- Scope
- Malicious campaigns targeting Italy or otherwise affecting Italy during the September 19–25 reporting week; the year is not disclosed.
- Sample Size
- 182 campaigns: 142 targeting Italy and 40 generic campaigns that also affected Italy.
- Key Statistics
- CERT-AGID identified 1,411 indicators of compromise and made them available to accredited entities; their values are not provided in the article.
- The campaigns used 24 themes.
- The refund theme appeared in 46 Italian phishing campaigns impersonating Agenzia delle Entrate.
- The unpaid-fine theme appeared in 35 Italian phishing campaigns delivered by email or SMS.
- CERT-AGID identified 14 malware families affecting Italy and 32 brands involved in phishing campaigns.
MITRE ATT&CK
Malware
AgentTeslaAgentTesla – Rilevate una campagna italiana a tema “Documenti” e sette campagne generiche “Prezzi”, “Contratti”, “Delivery”, “Booking”, “Pagamenti”, “Documenti” e “Fattura” che hanno utilizzato file GZ, JS, RAR, ZIP eAsyncRATAsyncRat – Scoperte una campagna italiana “Ordine” e tre campagne generiche ad argomento “Ordine” e “Prezzi” diffuse tramite archivi RAR e 7Z.BingoModUsato inoltre per veicolare i malware BingoMod, PureLogs Stealer, RemControl, Remcos e XWorm.FormBookFormBook – Scoperte due campagne generiche “Documenti” e “Fattura” diffuse tramite archivi ZIP e TAR.GuloaderGuloader – Osservate una campagna italiana “Pagamenti” e una campagna generica “Ordine”.MassLoggerMassLogger – Individuate una campagna italiana “Pagamenti” e una campagna generica “Ordine”, diffuse via ZIP, RAR e script JS.MintsLoaderIl CERT-AGID ha avuto evidenza di una nuova campagna che sfrutta caselle PEC compromesse per distribuire il malware MintsLoader ad altri indirizzi di posta elettronica certificata.PhantomStealerIndividuati infine i malware PhantomStealer, RemControl, ScreenConnect, StreamRat veicolati tramite campagne sia italiane che generiche.PureLogs StealerUsato inoltre per veicolare i malware BingoMod, PureLogs Stealer, RemControl, Remcos e XWorm.RemControlUsato inoltre per veicolare i malware BingoMod, PureLogs Stealer, RemControl, Remcos e XWorm.Remcos RATUsato inoltre per veicolare i malware BingoMod, PureLogs Stealer, RemControl, Remcos e XWorm.StreamRatIndividuati infine i malware PhantomStealer, RemControl, ScreenConnect, StreamRat veicolati tramite campagne sia italiane che generiche.XWormUsato inoltre per veicolare i malware BingoMod, PureLogs Stealer, RemControl, Remcos e XWorm.