Cisco Talos: Malware campaign is delivering to businesses multiple types of malware. Malware includes Trojans designed to steal banking credentials and other financial information. The campaign uses a crypter that’s designed to alter the malicious code to make it more difficult for security tools to detect. The threat actors behind this campaign are taking advantage of legitimate hosting platforms, such as Google Drive, to obscure malicious files designed to deliver malware to compromised devices. The malware includes Gozi ISFB, Zloader, Smoke loader, Oski, AveMaria and malicious versions of Cobalt Strike.”]
Source: https://www.databreachtoday.com/salfram-email-campaign-spreads-malware-to-businesses-a-14948

