MintsLoader via PEC: falsi solleciti di pagamento per diffondere malware

Summary
CERT-AGID reported and disrupted a MintsLoader campaign that used compromised PEC accounts to send convincing fake unpaid-invoice reminders. ZIP attachments contained HTML files that downloaded JavaScript, which used Windows components and PowerShell to execute MintsLoader and deliver further malware, described as RATs or stealers. CERT-AGID shared campaign indicators with accredited organizations and recommends caution with unexpected payment-related PEC messages and ZIP attachments.
Key points
- The messages were sent from real but compromised PEC accounts, so a legitimate-looking sender did not establish that the message or attachment was safe.
- The infection chain was PEC message → ZIP archive → HTML → JavaScript → PowerShell → MintsLoader → further malware.
- The campaign used frequently changing download addresses, including DGA techniques previously observed in MintsLoader campaigns.
- CERT-AGID said the addresses in analyzed files were initially inactive and became operational on the morning of September 24; it had seen a similar activation pattern in earlier campaigns.
- CERT-AGID coordinated response efforts with PEC providers and shared the campaign’s indicators through its IoC feed with accredited organizations.
- Users should treat unexpected PEC messages about invoices or payments, especially those with ZIP attachments, with caution and can forward suspicious messages to CERT-AGID for verification.
Attack Vectors
- Fake invoice-payment reminders sent from compromised PEC accounts
- ZIP attachments containing HTML files that download JavaScript
- JavaScript execution using Windows components and PowerShell
Defensive Notes
- Do not assume a PEC message or its attachment is safe because the sender appears legitimate.
- Use caution with unexpected payment-related messages containing ZIP attachments.
- Forward suspicious messages to CERT-AGID for verification.
- CERT-AGID shared campaign indicators with accredited organizations for detection and blocking.
Tags
Threat ResearchMalware DeliveryPhishingCompromised Email Accounts
MITRE ATT&CK
T1059.001The infection chain used PowerShell to run further stages.T1105The HTML file contacted attacker infrastructure and downloaded a JavaScript file.T1204.002The infection chain began when the recipient opened the ZIP attachment and its HTML file.T1566.001The campaign delivered malicious ZIP attachments in invoice-themed PEC messages.