Attackers Targeting Teachers with Ransomware Disguised as Class Assignments
Students and school systems have faced unique problems this year, and these messages take advantage of widespread technological difficulties accompanying online learning. The messages pose as a parent or guardian submitting an assignment on a student’s behalf, claiming that the student has encountered technical issues when trying to submit the assignment themselves. This campaign was very small, this and other actors may continue using themes of technology issues and online learning to lend legitimacy and urgency to their lures. The targets of this campaign were individual teachers, their email addresses likely pulled from public pages of a school website. Masquerading as the assignment is an attached malicious document that leads to the download of a custom ransomware payload. These messages seek to take advantage of widespread technology issues facing students, their families, and educators.
Indicator of Compromise
hxxps[:]//notabug[.]org/Microsoft-Templates/Template/raw/master/template1.dotm
hxxps[:]//notabug[.]org/Microsoft-Templates/Template/raw/master/irving.exe
hxxps[:]//notabug[.]org/Microsoft-Templates/Template/raw/master/alderson.exe
File Hashes
34842eff9870ea15ce3b3f3ec8d80c6fd6a22f65b6bae187d8eca014f11aafa5
e3420497b54be31b45ba2c344806a26f1d2f28ea388623984341bf585cb78391
6e9094fb4c9c24ca08435013e6ffa3bce6bb46c88d33136876e70f8b844578ad
225e19abba17f70df00562e89a5d4ad5e3818e40fd4241120a352aba344074f4
Comments
Post a Comment