{"id":17159,"date":"2021-12-23T10:39:58","date_gmt":"2021-12-23T15:39:58","guid":{"rendered":"https:\/\/www.technewsday.com\/?p=17159"},"modified":"2021-12-23T10:39:59","modified_gmt":"2021-12-23T15:39:59","slug":"dridex-lures-employees-to-open-malicious-docs-via-fake-emails","status":"publish","type":"post","link":"https:\/\/technewsday.com\/staging\/dridex-lures-employees-to-open-malicious-docs-via-fake-emails\/","title":{"rendered":"Dridex Lures Employees To Open Malicious Docs Via Fake  Emails"},"content":{"rendered":"\n<p>Dridex, banking malware is currently being used to deceive employees into clicking on malicious Excel documents.<\/p>\n\n\n\n<p>The malicious documents were sent to employees via fake employee termination emails.<\/p>\n\n\n\n<p>These emails use the subject line &#8220;Employee Termination.&#8221; The content informs recipients that their employment will end on December 24th, 2021.<\/p>\n\n\n\n<p>The email pointed out that &#8220;this decision is not reversible.&#8221; Embedded in the email is an attached Excel password-protected spreadsheet named &#8216;TermLetter.xls.&#8221;<\/p>\n\n\n\n<p>As soon as an employee opens the Excel spreadsheet and enters the password, a blurry &#8220;Personnel Action Form&#8221; appears, asking them to &#8220;Enable Content&#8221; to display it properly.<\/p>\n\n\n\n<p>Once activated, the victims receive a &#8220;Merry X-Mas Dear Employees!&#8221; pop-up message. Unknown to the victims, a malicious HTA file was stored in the C:\\ ProgramData folder during the process. HTA contains a malicious VBScript that downloads Dridex from Discord to infect the device.<\/p>\n\n\n\n<p>In order to mitigate this type of attack, users who receive such emails are advised to contact their human resources department or employees before opening the email.<\/p>\n\n\n<p>For more information, read the <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/dridex-malware-trolls-employees-with-fake-job-termination-emails\/\" target=\"_blank\" rel=\"noopener\">original story<\/a> in BleepingComputer.<\/p>","protected":false},"excerpt":{"rendered":"<p>Dridex, banking malware is currently being used to deceive employees into clicking on malicious Excel documents.<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[16,9],"tags":[],"class_list":["post-17159","post","type-post","status-publish","format-standard","hentry","category-security","category-todays-news"],"acf":[],"_links":{"self":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/17159","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/comments?post=17159"}],"version-history":[{"count":3,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/17159\/revisions"}],"predecessor-version":[{"id":17195,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/17159\/revisions\/17195"}],"wp:attachment":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/media?parent=17159"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/categories?post=17159"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/tags?post=17159"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}