CERT-AGID Reports 219 Malicious Campaigns Affecting Italy

Summary
CERT-AGID reported 219 malicious campaigns affecting Italy during Sept. 26–Oct. 2 and shared 1,436 IoCs. The weekly summary covers phishing lures, malware, targeted CNR credential theft, and research finding over 500,000 exposed credentials.
Key points
- CERT-AGID analyzed 219 campaigns: 185 targeting Italy and 34 generic campaigns that also affected Italy; it provided 1,436 IoCs to accredited entities.
- The leading phishing themes were tax refunds (51 campaigns), unpaid fines (44), banking (35), and prize offers (12).
- A targeted phishing campaign impersonated the CNR webmail and referenced Outlook to steal employees’ institutional email credentials.
- Fifteen malware families were observed. AgentTesla, Remcos, FormBook, XWorm, and others were commonly delivered through email attachments in archives such as ZIP and RAR.
- Two banking-themed campaigns distributed BingoMod and RatHat through SMS links to APK files.
- The roundup also noted research identifying more than 500,000 valid credentials—including API keys, access tokens, and database credentials—in the The Stack v3 dataset.
Article Details
- Publisher
- CERT-AGID
- Scope
- Malware and phishing activity affecting Italy during the week identified as September 26–October 2; the year is not disclosed.
- Sample Size
- 219 malicious campaigns analyzed by CERT-AGID.
- Key Statistics
- Of 219 malicious campaigns, 185 targeted Italy and 34 were generic campaigns that also affected Italy.
- CERT-AGID identified 1436 indicators of compromise and made them available to accredited entities; the article does not list their values.
- Campaigns used 24 themes. Italian phishing campaigns included 51 refund-themed campaigns impersonating Agenzia delle Entrate, 44 fine-themed campaigns, and 35 banking-themed campaigns.
- The weekly findings included 15 malware families affecting Italy and 45 brands involved in phishing.
- Separately, Truffle Security reported finding more than 500,000 valid credentials in The Stack v3, a dataset built from public GitHub repositories for training code-focused AI models.
MITRE ATT&CK
Malware
AgentTeslaAgentTesla – Rilevate una campagna italiana a tema “Ordine” e sei campagne generiche “Delivery”, “Fattura”, “Ordine”, “Pagamenti” e “Documenti” che hanno sfruttato file ZIP, TAR, RAR e XLS.AsyncRAT“Ordine”, “Fattura”, “Delivery”, “Documenti”, “Aggiornamenti” e “Contratti”, e riconducibili ai malware AsyncRat, Grandoreiro, Guloader, PhantomStealer, PureRat, SectopRat e VipKeylogger.BingoModUsato inoltre per veicolare i malware BingoMod, XWorm e RatHat.FormBookFormBook – Scoperte due campagne italiane ad argomento “Delivery” e “Pagamenti” e due campagne generiche a tema “Pagamenti” distribuite con archivi 7Z, RAR e ZIP.Grandoreiro“Delivery”, “Documenti”, “Aggiornamenti” e “Contratti”, e riconducibili ai malware AsyncRat, Grandoreiro, Guloader, PhantomStealer, PureRat, SectopRat e VipKeylogger.Guloader“Documenti”, “Aggiornamenti” e “Contratti”, e riconducibili ai malware AsyncRat, Grandoreiro, Guloader, PhantomStealer, PureRat, SectopRat e VipKeylogger.MassLoggerMassLogger – Rilevate due campagne generiche “Pagamenti” e “Fattura” diffuse attraverso archivi RAR e GZ.PhantomStealer“Aggiornamenti” e “Contratti”, e riconducibili ai malware AsyncRat, Grandoreiro, Guloader, PhantomStealer, PureRat, SectopRat e VipKeylogger.PureLogs StealerPureLogs Stealer – Scoperte due campagne generiche a tema “Booking” e “Ordine” che allegavano ZIP e RAR alle mail.PureRate “Contratti”, e riconducibili ai malware AsyncRat, Grandoreiro, Guloader, PhantomStealer, PureRat, SectopRat e VipKeylogger.RatHatUsato inoltre per veicolare i malware BingoMod, XWorm e RatHat.Remcos RATRemcos – Individuate due campagne italiane “Ordine” e “Documenti” e quattro campagne generiche “Prezzi”, “Contratti” e “Ordine” veicolate tramite ZIP, XLS, GZ e RAR.SectopRATe “Contratti”, e riconducibili ai malware AsyncRat, Grandoreiro, Guloader, PhantomStealer, PureRat, SectopRat e VipKeylogger.VipKeyloggere riconducibili ai malware AsyncRat, Grandoreiro, Guloader, PhantomStealer, PureRat, SectopRat e VipKeylogger.XWormUsato inoltre per veicolare i malware BingoMod, XWorm e RatHat.
Products
GitHuboltre 500.000 credenziali valide nel dataset The Stack v3, costruito a partire da repository pubblici GitHub e utilizzato per l’addestramento di modelli di Intelligenza Artificiale dedicati al codice.OutlookIl CERT-AGID ha individuato e contrastato una campagna di phishing mirato che riproduce una falsa webmail del Consiglio Nazionale delle Ricerche (CNR), con riferimenti a Outlook.