MetaStealer Mar 2022 Campaign - Phishing Email TTP T1566

Strike ID:
P22-e2pm1
CVSS:
4.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
False Positive:
f
Variants:
8
Year:
2022

Description

This strike simulates a phishing email that has been linked with the MetaStealer Mar 2022 Campaign. It tries to trick the user into downloading a malicious zip archive file. This archive contains an XLS file that contains an embedded macro. Once executed this macro makes a request to Github to download a malicious data binary used to establish persistence on the host.

References