A recent campaign leveraged a previously compromised email account belonging to an employee of a prominent Chamber of Commerce. The attacker sent generic responses to existing threads, attaching a malicious Microsoft Office document. Abusing compromised trusted senders is a powerful persuasion tactic, which greatly increases the chances of opening the malicious attachment even by a trained recipient. The payload in this case was a Gozi ISFB/Ursnif malware, capable of stealing sensitive data from a victim. Minervas Malicious Documents Protection capabilities prevents this evasive threat and provide useful data to SOC and IR teams.”]

