The Cofense Phishing Defense Center has observed a new phishing campaign that spoofs a PDF attachment to deliver the notorious Adwind malware. This campaign was found explicitly in national grid utilities infrastructure. Adwind, aka JRAT or SockRat, is sold as a malware-as-a-service where users can purchase access to the software for a small subscription-based fee. The malware boasts the following features:Harvests credentials from Chrome, IE and Edge, accesses webcam, record video and take photos.”]
Source: https://cofense.com/new-phishing-campaign-bypasses-microsoft-atp-deliver-adwind-utilities-industry/