An ongoing malicious email campaign is masquerading as an unpaid invoice, a Kaspersky Lab researcher said Thursday.
In this recurring campaign, cyber-criminals are sending out emails with a malicious PDF attachment masquerading as notices and reminders to pay overdue bills, Ben Godwood, a researcher with Kaspersky Lab, wrote on the SecureList blog on Thursday. The email campaign appears to have been ongoing since November, and follow a set schedule, hitting victim inboxes either on the 4th or the 21st of the month.
Kaspersky Lab detected the latest batch of specially crafted PDF messages on March 4, Godwood said. Most of the emails were sent from German IP addresses, and appear to have been sent from compromised home computers, Godwood said. The attack emails were mostly sent from German IP addresses in the latest iteration of the campaign, Godwood said, previous messages appear to have been sent from infected bots in other countries.
Kaspersky blocked "a large number of emails" with the filename including the word "invoice" on Feb. 21, Jan. 4, and Nov. 21, Godwood said. The messages originated from various countries, including South Africa, United States, Australia, and Japan, and the attack code attempted to download additional malware from servers in Germany, United Kingdom, Sweden, and Israel.
"Looking back through our past feedback data, we noticed similar patterns on the 4th and 21st of several months," Godwood said.
When the victim opened the file, the attack code downloaded an executable file. The Trojan regularly communicates with a remote server after it installs itself.
If you receive an invoice on March 21 or April 4, be extra cautious, Godwood said. However, since the criminals can always change the dates they run the scam, "it's better to be cautious all the time," he said.