Phorpiex botnet sent millions of phishing emails to deliver LockBit Black ransomware

Experts reported that since April, the Phorpiex botnet sent millions of phishing emails to spread LockBit Black ransomware

Security Affairs

If you've been monitoring that #phorpiex "Your Document" with document\.zip from Jenny @ gsd . com, it's now dropping #lockbit hosted at:

http:// 193.233 .132 .177/lbb.exe

https://app.any.run/tasks/206f3ae9-cdd7-4ee4-a1b5-f9cccf3541fc

Analysis Document.doc.scr.exe (MD5: A1784AA6993AF25CB55A36154A954649) Malicious activity - Interactive analysis ANY.RUN

Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.

A (late again :( ) csv formatted list of #malspam campaigns that crossed my path in March to include subjects, malware, hashes, c2's, and email exfil addresses. Side note; #phorpiex campaign at 35K+ is the largest I've seen and ongoing:

https://gist.github.com/silence-is-best/e0fa9b5c4d5028a2e853d98b702cacdf

#retrohunt

March Malspam Campaigns

March Malspam Campaigns. GitHub Gist: instantly share code, notes, and snippets.

Gist

Campagne #Malware #Italy Week 13

πŸ‘»πŸ’£πŸ”₯☠️
#AgentTesla: Pagamenti
#Remcos: Delivery
#Irata: APK Bank
#Phorpiex: Documenti
#Guloader: Ordine
#PlanetStealer: Conferma
#Lokibot: Preventivo
#Pikabot: Resend

#mwitaly

Threat Roundup for April 30 to May 7

A blog from the world class Intelligence Group, Talos, Cisco's Intelligence Group

Threat Roundup for April 16 to April 23

A blog from the world class Intelligence Group, Talos, Cisco's Intelligence Group

Threat Roundup for March 26 to April 2

A blog from the world class Intelligence Group, Talos, Cisco's Intelligence Group

Threat Roundup for January 15 to January 22 - Today, Talos is publishing a glimpse into the most prevalent threats we've observed between Jan. 15 ... http://feedproxy.google.com/~r/feedburner/Talos/~3/X7WNdAYBzrs/threat-roundup-0115-0122.html #vulnerabilities #threatroundup #ciscotalos #gh0strat #glupteba #phorpiex #gamarue #malware #emotet #ursnif #talos #razy #shiz
Threat Roundup for January 15 to January 22

A blog from the world class Intelligence Group, Talos, Cisco's Intelligence Group

Threat Roundup for December 11 to December 18 - Today, Talos is publishing a glimpse into the most prevalent threats we've observed between Dec. 11 ... http://feedproxy.google.com/~r/feedburner/Talos/~3/tSQqOPOkcsg/threat-roundup-1211-1218.html #vulnerabilities #threatroundup #ciscotalos #tinybanker #darkcomet #phorpiex #tovkater #gamarue #lokibot #malware #cerber #dridex #talos #razy
Threat Roundup for November 29 to December 6 - Today, Talos is publishing a glimpse into the most prevalent threats we've observed between Nov. 29 ... more: http://feedproxy.google.com/~r/feedburner/Talos/~3/VB8_-mJ1xSE/threat-roundup-1129-1206.html #vulnerabilities #threatroundup #gh0strat #phorpiex #lokibot #malware #netwire #cerber #emotet #tofsee #talos #zbot
Threat Roundup for November 29 to December 6

A blog from the world class Intelligence Group, Talos, Cisco's Intelligence Group