MintsLoader via PEC: falsi solleciti di pagamento per diffondere malware

· Original article ↗

Summary

CERT-AGID reported and disrupted a MintsLoader campaign that used compromised PEC accounts to send convincing fake unpaid-invoice reminders. ZIP attachments contained HTML files that downloaded JavaScript, which used Windows components and PowerShell to execute MintsLoader and deliver further malware, described as RATs or stealers. CERT-AGID shared campaign indicators with accredited organizations and recommends caution with unexpected payment-related PEC messages and ZIP attachments.

Key points

  • The messages were sent from real but compromised PEC accounts, so a legitimate-looking sender did not establish that the message or attachment was safe.
  • The infection chain was PEC message → ZIP archive → HTML → JavaScript → PowerShell → MintsLoader → further malware.
  • The campaign used frequently changing download addresses, including DGA techniques previously observed in MintsLoader campaigns.
  • CERT-AGID said the addresses in analyzed files were initially inactive and became operational on the morning of September 24; it had seen a similar activation pattern in earlier campaigns.
  • CERT-AGID coordinated response efforts with PEC providers and shared the campaign’s indicators through its IoC feed with accredited organizations.
  • Users should treat unexpected PEC messages about invoices or payments, especially those with ZIP attachments, with caution and can forward suspicious messages to CERT-AGID for verification.

Attack Vectors

  • Fake invoice-payment reminders sent from compromised PEC accounts
  • ZIP attachments containing HTML files that download JavaScript
  • JavaScript execution using Windows components and PowerShell

Defensive Notes

  • Do not assume a PEC message or its attachment is safe because the sender appears legitimate.
  • Use caution with unexpected payment-related messages containing ZIP attachments.
  • Forward suspicious messages to CERT-AGID for verification.
  • CERT-AGID shared campaign indicators with accredited organizations for detection and blocking.

Tags

Threat ResearchMalware DeliveryPhishingCompromised Email Accounts

MITRE ATT&CK

Malware

Products

Tools

Countries

Related Articles