The SANS Internet Storm Centre is reporting another spam email attack doing the rounds with a new payload.
TA551 (Shathak) pushes IcedID (Bokbot) (sans.edu)

The important things to take away from this are:
- In real world situations ransomware has been delivered to companies using these methods
- Keep your spam filters and anti-virus packages up to date
- Default security settings in Windows and Microsoft Office 2019 form part of your defence against these types of attacks – check they are correct.
- Remember an approved back-up solution is your best recovery tool if you are infected
- **** You have to get it right every time, the attacker has only to get it right once for you to need that back-up ****
- Good training and policies and procedures, backed up with an effective incident response plan are all part of your multi-layered defence in depth.
Clive Catton MSc (Cyber Security) – by-line and other articles