In mid-March 2021, we observed two new spam campaigns. The messages in both cases were written in English and contained ZIP attachments or links to ZIP files. Further research revealed that both campaigns ultimately aimed to distribute banking Trojans. The payload in most cases was IcedID (Trojan-Banker.Win32.IcedID) The main body is hidden in a PNG image, which is downloaded and decrypted by the downloader. In the past, the main body was distributed as a shellcode hidden in the main image.”]
Source: https://securelist.com/malicious-spam-campaigns-delivering-banking-trojans/102917/

