Malware Spam in the wild

The SANS Internet Storm Centre is reporting another spam email attack doing the rounds with a new payload.

TA551 (Shathak) pushes IcedID (Bokbot) (sans.edu)

Cybersecurity email threat
The attackers only have to get through once!

The important things to take away from this are:

  • In real world situations ransomware has been delivered to companies using these methods
  • Keep your spam filters and anti-virus packages up to date
  • Default security settings in Windows and Microsoft Office 2019 form part of your defence against these types of attacks – check they are correct.
  • Remember an approved back-up solution is your best recovery tool if you are infected
  • **** You have to get it right every time, the attacker has only to get it right once for you to need that back-up ****
  • Good training and policies and procedures, backed up with an effective incident response plan are all part of your multi-layered defence in depth.

Clive Catton MSc (Cyber Security) – by-line and other articles