CERT-AGID Reports 219 Malicious Campaigns Affecting Italy

· Original article ↗

Summary

CERT-AGID reported 219 malicious campaigns affecting Italy during Sept. 26–Oct. 2 and shared 1,436 IoCs. The weekly summary covers phishing lures, malware, targeted CNR credential theft, and research finding over 500,000 exposed credentials.

Key points

  • CERT-AGID analyzed 219 campaigns: 185 targeting Italy and 34 generic campaigns that also affected Italy; it provided 1,436 IoCs to accredited entities.
  • The leading phishing themes were tax refunds (51 campaigns), unpaid fines (44), banking (35), and prize offers (12).
  • A targeted phishing campaign impersonated the CNR webmail and referenced Outlook to steal employees’ institutional email credentials.
  • Fifteen malware families were observed. AgentTesla, Remcos, FormBook, XWorm, and others were commonly delivered through email attachments in archives such as ZIP and RAR.
  • Two banking-themed campaigns distributed BingoMod and RatHat through SMS links to APK files.
  • The roundup also noted research identifying more than 500,000 valid credentials—including API keys, access tokens, and database credentials—in the The Stack v3 dataset.

Article Details

Publisher
CERT-AGID
Scope
Malware and phishing activity affecting Italy during the week identified as September 26–October 2; the year is not disclosed.
Sample Size
219 malicious campaigns analyzed by CERT-AGID.
Key Statistics
  • Of 219 malicious campaigns, 185 targeted Italy and 34 were generic campaigns that also affected Italy.
  • CERT-AGID identified 1436 indicators of compromise and made them available to accredited entities; the article does not list their values.
  • Campaigns used 24 themes. Italian phishing campaigns included 51 refund-themed campaigns impersonating Agenzia delle Entrate, 44 fine-themed campaigns, and 35 banking-themed campaigns.
  • The weekly findings included 15 malware families affecting Italy and 45 brands involved in phishing.
  • Separately, Truffle Security reported finding more than 500,000 valid credentials in The Stack v3, a dataset built from public GitHub repositories for training code-focused AI models.

MITRE ATT&CK

Malware

AgentTeslaAgentTesla – Rilevate una campagna italiana a tema “Ordine” e sei campagne generiche “Delivery”, “Fattura”, “Ordine”, “Pagamenti” e “Documenti” che hanno sfruttato file ZIP, TAR, RAR e XLS.AsyncRAT“Ordine”, “Fattura”, “Delivery”, “Documenti”, “Aggiornamenti” e “Contratti”, e riconducibili ai malware AsyncRat, Grandoreiro, Guloader, PhantomStealer, PureRat, SectopRat e VipKeylogger.BingoModUsato inoltre per veicolare i malware BingoMod, XWorm e RatHat.FormBookFormBook – Scoperte due campagne italiane ad argomento “Delivery” e “Pagamenti” e due campagne generiche a tema “Pagamenti” distribuite con archivi 7Z, RAR e ZIP.Grandoreiro“Delivery”, “Documenti”, “Aggiornamenti” e “Contratti”, e riconducibili ai malware AsyncRat, Grandoreiro, Guloader, PhantomStealer, PureRat, SectopRat e VipKeylogger.Guloader“Documenti”, “Aggiornamenti” e “Contratti”, e riconducibili ai malware AsyncRat, Grandoreiro, Guloader, PhantomStealer, PureRat, SectopRat e VipKeylogger.MassLoggerMassLogger – Rilevate due campagne generiche “Pagamenti” e “Fattura” diffuse attraverso archivi RAR e GZ.PhantomStealer“Aggiornamenti” e “Contratti”, e riconducibili ai malware AsyncRat, Grandoreiro, Guloader, PhantomStealer, PureRat, SectopRat e VipKeylogger.PureLogs StealerPureLogs Stealer – Scoperte due campagne generiche a tema “Booking” e “Ordine” che allegavano ZIP e RAR alle mail.PureRate “Contratti”, e riconducibili ai malware AsyncRat, Grandoreiro, Guloader, PhantomStealer, PureRat, SectopRat e VipKeylogger.RatHatUsato inoltre per veicolare i malware BingoMod, XWorm e RatHat.Remcos RATRemcos – Individuate due campagne italiane “Ordine” e “Documenti” e quattro campagne generiche “Prezzi”, “Contratti” e “Ordine” veicolate tramite ZIP, XLS, GZ e RAR.SectopRATe “Contratti”, e riconducibili ai malware AsyncRat, Grandoreiro, Guloader, PhantomStealer, PureRat, SectopRat e VipKeylogger.VipKeyloggere riconducibili ai malware AsyncRat, Grandoreiro, Guloader, PhantomStealer, PureRat, SectopRat e VipKeylogger.XWormUsato inoltre per veicolare i malware BingoMod, XWorm e RatHat.

Products

Countries

Industries

Related Articles