August 23, 2016 By Larry Loeb 2 min read

When the Necurs botnet seemingly went down in June of this year — only to return to action three weeks later — it seemed to also take the Dridex malware infection campaign with it. Unfortunately, that’s not the case.

Dridex Malware Is Back

Dridex is back, according to Proofpoint, but with a different way of doing things. The criminals behind it seem to have changed their ways and are now sending out smaller Dridex spam campaigns. Rather than send emails to random users, the campaigns have begun to target businesses.

Proofpoint found that the criminals delivered tens of thousands of messages on Aug. 15 and 16. They primarily targeted financial services and manufacturing organizations. However, the volume of this recent activity does not even approach the multimillion message campaigns that occurred in May.

Smaller Target, Higher Stakes

The botnet delivering the attack contained configurations for banking sites in the U.K., Australia, France and the U.S. The emails it distributed contained macro-laden Word attachments. The messages themselves appeared to be normal business communications, such as an order confirmation.

This recent explosion of Dridex targets a number of back-end payment processing, point-of-sale (POS) and remote management applications, according to Proofpoint. Dridex has gone after these types of applications in the past.

It seems that criminals are trying to compromise employees and people with access to valuable information. The Dridex Trojan is capable of phishing out victim credentials for many financial applications.

Proofpoint detected the miscreants using the Neutrino exploit kit to deliver the Trojan in the U.K. and Switzerland. This is a technique the group hasn’t employed much in the past.

New Lease on Life

Proofpoint explained that although most high-volume malware campaigns tend to distribute Locky-associated payloads almost exclusively, Dridex may be “taking on a new life” due to the shift to more targeted distribution. Cybercriminals using Dridex have avoided saturating target countries and are instead targeting a smaller number of large financial services organizations.

The changes to Dridex distribution mean that companies must be alert to the possibility of an attack. What happened in Switzerland could happen anywhere.

More from

When ransomware kills: Attacks on healthcare facilities

4 min read - As ransomware attacks continue to escalate, their toll is often measured in data loss and financial strain. But what about the loss of human life? Nowhere is the ransomware threat more acute than in the healthcare sector, where patients’ lives are literally on the line.Since 2015, there has been a staggering increase in ransomware attacks on healthcare facilities. And the impacts are severe: Diverted emergency services, delayed critical treatments and even fatalities. Meanwhile, the pledge some ransomware groups made during…

AI and cloud vulnerabilities aren’t the only threats facing CISOs today

6 min read - With cloud infrastructure and, more recently, artificial intelligence (AI) systems becoming prime targets for attackers, security leaders are laser-focused on defending these high-profile areas. They’re right to do so, too, as cyber criminals turn to new and emerging technologies to launch and scale ever more sophisticated attacks.However, this heightened attention to emerging threats makes it easy to overlook traditional attack vectors, such as human-driven social engineering and vulnerabilities in physical security.As adversaries exploit an ever-wider range of potential entry points…

4 trends in software supply chain security

4 min read - Some of the biggest and most infamous cyberattacks of the past decade were caused by a security breakdown in the software supply chain. SolarWinds was probably the most well-known, but it was not alone. Incidents against companies like Equifax and tools like MOVEit also wreaked havoc for organizations and customers whose sensitive information was compromised.Expect to see more software supply chain attacks moving forward. According to ReversingLabs' The State of Software Supply Chain Security 2024 study, attacks against the software…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today