An ongoing phishing campaign launched by TA505 is using attachments featuring HTML redirectors for delivering malicious Excel docs. When opened, the HTML leads to the download Dudear, a malicious macro-laden Excel file that drops the payload. This is the first time that TA505 group is using this tactic, in the past, the group used spam messages carrying the malware as an attachment or used malicious URLs. TA505 hacking group has been active since 2014 focusing on Retail and banking sectors. The group was involved in campaigns aimed at distributing the Dridex banking Trojan, Locky, BitPaymer, Philadelphia, GlobeImposter, and Jaff ransomware families.”]
Source: https://securityaffairs.co/wordpress/97150/breaking-news/ta505-changes-tactics.html

