Malicious phishing scam disguised as HIV results


Security researchers have discovered a new phishing scam which lures users into opening a malicious Excel document by pretending to offer their HIV test results.
Phishing campaigns have seen a huge increase over the past year as the scammers behind them have begun employing new tactics to trick users into falling for their schemes.
This time though, they may have taken things too far as researchers at Proofpoint have observed scammers sending phishing emails with malicious Excel spreadsheets pretending to be patients’ HIT test results from Vanderbilt University.
While those who are more observant may notice that the university’s name is misspelled in the contact of the email as “Vanderbit”, most users likely won’t as the rest of the phishing email appears as if it comes directly from the university.
Malicious Excel file
The phishing emails sent out in the campaign all contain an attachment named “TestResults.xlsb” that requires users to ‘Enable Content’ to view their test results.
If a user does decide to enable content, malicious macros are then executed which download and install the Koadic penetration test and post-exploitation toolkit.
Through Koadic, the attackers are able to gain complete control over the infected computer and from there they can execute any command they like to download additional malware or steal files from the machine.
Senior director of threat research and detection at Proofpoint, Sherrod DeGrippo provided further insight on how cybercriminals are now using health-related lures to trick users into falling for phishing scams in a blog post, saying:
“This latest campaign serves as a reminder that health-related lures didn’t start and won’t stop with the recent Coronavirus-themed lures we observed. They are a constant tactic as attackers recognize the utility of the health-related “scare factor.” We encourage users to treat health-related emails with caution, especially those that claim to have sensitive health-related information. Sensitive health-related information is typically safely transmitted using secured messaging portals, over the phone, or in-person. If you receive an email that claims to have sensitive health-related information, don’t open the attachments. Instead, visit your medical provider’s patient portal directly, call your doctor, or make an appointment to directly confirm any medical diagnosis or test results.”
Via BleepingComputer
Security researchers have discovered a new phishing scam which lures users into opening a malicious Excel document by pretending to offer their HIV test results. Phishing campaigns have seen a huge increase over the past year as the scammers behind them have begun employing new tactics to trick users into…
Recent Posts
- A data center in every home! Energy company wants to heat your water for (almost) free but there’s a catch
- Like the Crucial T705 but more affordable? Micron 4600 PCIe Gen5 SSD comes painfully close to its award-winning sibling
- Vizio Elevate SE 5.1.2 Soundbar Review: Cheap Thrills
- Our favorite apps for listening to music
- Leaked hands-on Samsung Galaxy S25 Edge video hints at its design and specs – and then disappears
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010