A malspam campaign targeting potential German victims is actively distributing Sodinokibi ransomware via spam emails disguised as foreclosure notifications with malicious attachments. The malicious attachment named Mahnbescheid – Antwortbogen – Aktenzeichen 4650969334.doc will download the SodInokibi Ransomware to %Temp%Microsoft-Word.exe using an obfuscated VBA-based macro. The attackers are trying to trick their targets into reacting to the bait and to open the infected attachments.
Source: https://www.bleepingcomputer.com/news/security/sodinokibi-ransomware-pushed-via-foreclosure-warning-spam/

