December 20, 2021  —  Eric Swotinsky

New phishing campaigns steal credentials through malicious QR codes, PowerPoint files

There are a number of ways to increase password strength, but it all means nothing if your credentials are stolen. A series of new phishing campaigns shows increased focus on info-stealing tactics.

Customers of German banks Sparkasse and Volksbank Raiffeisenbank are being actively targeted with phishing emails. These malicious messages are using custom links, sometimes hidden behind a QR code, that lead to dangerous info-logging websites.

Another email wave recently seen in South Korea using malicious PowerPoint files, disguised as purchase orders. Rather than containing slides, however, these files use a VBA macro to load a remote HTML page, which starts a PowerShell script and ultimately injects the Agent Tesla infostealer malware into regAsm.exe using process-hollowing techniques. This malware steals passwords from local applications like browsers, VPNs, and email clients.

Acronis Advanced Email Security blocks malicious emails before they end up at your customers inbox. Should one of the attachments be opened anyway, then Acronis Cyber Protect will block the downloaded payload before it can do any damage to your system.