MintsLoader Campaign Uses Compromised Certified Email Accounts to Deliver Malware

· Original article ↗

Summary

CERT-AGID reports a campaign using compromised certified email accounts to send fake invoice reminders with ZIP attachments. The files launch a chain leading to MintsLoader and potentially RATs or stealers.

Key points

  • The campaign used compromised PEC accounts to send convincing fake payment reminders, including references to unpaid invoices.
  • Messages carried ZIP archives containing HTML files rather than the expected invoices.
  • Opening the HTML triggered a download chain involving JavaScript and PowerShell that executed MintsLoader, which can load other malware, including RATs and stealers.
  • The campaign used frequently changing retrieval addresses, including domains generated with DGA techniques.
  • Some attacker-controlled addresses were initially inactive and became operational on the morning of September 24.
  • CERT-AGID coordinated countermeasures with PEC providers and shared campaign indicators with accredited organizations.
  • CERT-AGID warns that a valid PEC sender does not rule out account compromise or make an attachment safe.

Article Details

Event Type
Malware distribution through fraudulent payment-reminder emails sent from compromised certified email (PEC) accounts
Impact
Opening the attached ZIP and its HTML file can start a chain that executes MintsLoader, which downloads and runs further malware. The article depicts RATs or stealers as possible final payloads but does not report a number of infected systems.

MITRE ATT&CK

Malware

Products

Related Articles