www.itfunk.orgwww.itfunk.orgwww.itfunk.org
  • Home
  • Tech News
    Tech NewsShow More
    Zero Trust: How a Security Idea Became a Blueprint
    41 Min Read
    Cybersecurity Law Expiration Could Unleash New Ransomware Surge – Former FBI Official Sounds the Alarm
    8 Min Read
    Under the Hood of Microsoft’s May 2025 Patch Tuesday: The CLFS and WinSock Problem Microsoft Can’t Seem to Fix
    7 Min Read
    The Hidden Sabotage: How Malicious Go Modules Quietly Crashed Linux Systems
    6 Min Read
    Agentic AI: The Next Frontier in Cybersecurity Defense and Risk​
    5 Min Read
  • Cyber Threats
    • Malware
    • Ransomware
    • Trojans
    • Adware
    • Browser Hijackers
    • Mac Malware
    • Android Threats
    • iPhone Threats
    • Potentially Unwanted Programs (PUPs)
    • Online Scams
    • Microsoft CVE Vulnerabilities
  • How To Guides
    How To GuidesShow More
    Tasksche.exe Malware
    Nviqri Someq Utils Unwanted Application
    4 Min Read
    How to Deal With Rbx.fund Scam
    4 Min Read
    How to Jailbreak DeepSeek: Unlocking AI Without Restrictions
    4 Min Read
    Why Streaming Services Geo-Restrict Content?
    10 Min Read
  • Product Reviews
    • Hardware
    • Software
  • IT/Cybersecurity Best Practices
    IT/Cybersecurity Best PracticesShow More
    Zero Trust: How a Security Idea Became a Blueprint
    41 Min Read
    Under the Hood of Microsoft’s May 2025 Patch Tuesday: The CLFS and WinSock Problem Microsoft Can’t Seem to Fix
    7 Min Read
    Affordable Endpoint Protection Platforms (EPP) for Small Businesses
    5 Min Read
    Outlaw Malware: A Persistent Threat Exploiting Linux Servers
    4 Min Read
    CVE-2024-48248: Critical NAKIVO Backup & Replication Flaw Actively Exploited—Patch Immediately
    6 Min Read
  • FREE SCAN
  • Cybersecurity for Business
Search
  • ABOUT US
  • TERMS AND SERVICES
  • SITEMAP
  • CONTACT US
© 2023 ITFunk.org. All Rights Reserved.
Reading: IcedID banking trojan tricks users with COVID-19 & FMLA (Family and Medical Leave Act) phishing emails
Share
Notification Show More
Font ResizerAa
www.itfunk.orgwww.itfunk.org
Font ResizerAa
  • Tech News
  • How To Guides
  • Cyber Threats
  • Product Reviews
  • Cybersecurity for Business
  • Free Scan
Search
  • Home
  • Tech News
  • Cyber Threats
    • Malware
    • Ransomware
    • Trojans
    • Adware
    • Browser Hijackers
    • Mac Malware
    • Android Threats
    • iPhone Threats
    • Potentially Unwanted Programs (PUPs)
    • Online Scams
  • How To Guides
  • Product Reviews
    • Hardware
    • Software
  • IT/Cybersecurity Best Practices
  • Cybersecurity for Business
  • FREE SCAN
Follow US
  • ABOUT US
  • TERMS AND SERVICES
  • SITEMAP
  • CONTACT US
© 2023 ITFunk.org All Rights Reserved.
www.itfunk.org > Blog > Cyber Threats > Trojans > IcedID banking trojan tricks users with COVID-19 & FMLA (Family and Medical Leave Act) phishing emails
Trojans

IcedID banking trojan tricks users with COVID-19 & FMLA (Family and Medical Leave Act) phishing emails

ITFunk Research
Last updated: October 24, 2023 4:34 pm
ITFunk Research
Share
IcedID banking trojan tricks users with COVID-19 & FMLA (Family and Medical Leave Act) phishing emails, and...
SHARE

Back in 2020, hackers attempted to capitalize on the Coronavirus (COVID-19) pandemic by using phishing campaigns. According to Juniper Networks’ Threat Labs researchers at the time, a COVID-19-related phishing campaign was found to be spreading the banking trojan IcedID. 

IcedID is a banking trojan that executes man-in-the-browser attacks to steal banking information and monitor financial transactions. Hackers lure victims into opening a set of malicious files attached to emails that utilize keywords such as COVID-19 and FMLA or (Family and Medical Leave Act). The emails are designed to convince recipients that the documents are coming from the U.S. Department of Labor and contain legitimate information.

Although the earlier versions of IcedID injected itself into svchost.exe and downloaded encrypted modules, the most recent campaign modifies those tactics by inserting itself into the msiexec.exe process. The infection comes in three stages. It starts with a phishing email containing a malicious Microsoft Office attachment. When opened, the file launches a second loader whose purpose is to download yet another IcedID loader. Then, a loader downloads the actual IcedID main module.

As for the delivery email itself, it’s loaded with broken English and typographical and grammatical errors. Like other COVID-19 phishing attempts, it contains a persuasive call-to-action, with references to the Families First Coronavirus Response Act that provides paid sick leave and expanded family and medical leave related to the coronavirus.

The phishing email reads in part:

“Dear employees, The following notice is written to all suitable workers in order to notify of a number of changes that have been constructed in the current FMLA with regards to the latest Coronavirus Response Act. To ask for leave based on the Family and Medical leave of Act (sic), remember to analyze the files very carefully, get informed about the adjustments that have been created, fill out the requestform (sic) and send to Human Resources until may (sic) 31st, 2020.”

Organizations that have been targeted by IcedID include Amazon, American Express, AT&T, Bank of America, Charles Schwab, Chase, J.P. Morgan, Wells Fargo, and others.

Other hackers have used phishing to capitalize on the Coronavirus pandemic by using bogus Gmail accounts to fool businesses in key industries to hand over their Google credentials. According to Google security researchers, some attacks have ensnared individuals with email invitations to sign up for phony COVID-19 notifications from the World Health Organization. In late April of 2020, the FBI said that the number of online crimes reported to its Crime Complaint Center had quadrupled to upwards of 4,000 incidents a day since the Coronavirus pandemic began in the U.S.

You Might Also Like

Trojan.IcedID.ANJ
SnakeDiskUSB Worm
ChillyHell Backdoor (macOS)
ZynorRAT Trojan
kkRAT Trojan
TAGGED:Email ScamsMalwarePhishingPhishing EmailsTrojans

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Copy Link Print
Share
Previous Article Java-based malware STRRAT steals credentials & comes with .CRIMSON ransomware module
Next Article Ragnar Locker ransomware targets the Remote Management Software used by Managed Service Providers 
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Scan Your System for Malware

Don’t leave your system unprotected. Download SpyHunter today for free, and scan your device for malware, scams, or any other potential threats. Stay Protected!

Download SpyHunter 5
Download SpyHunter for Mac
✅ Free Scan Available • ⭐ Catches malware instantly
//

Check in Daily for the best technology and Cybersecurity based content on the internet.

Quick Link

  • ABOUT US
  • TERMS AND SERVICES
  • SITEMAP
  • CONTACT US

Support

Sign Up for Our Newesletter

Subscribe to our newsletter to get our newest articles instantly!

 

www.itfunk.orgwww.itfunk.org
© 2023 www.itfunk.org. All Rights Reserved.
  • ABOUT US
  • TERMS AND SERVICES
  • SITEMAP
  • CONTACT US
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?