[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/silverterrier-covid-19-themed-business-email-compromise/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/silverterrier-covid-19-themed-business-email-compromise/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Business Email Compromise](https://unit42.paloaltonetworks.com/category/business-email-compromise/ "Business Email Compromise")  
  [Business Email Compromise](https://unit42.paloaltonetworks.com/category/business-email-compromise/)

# SilverTerrier: New COVID-19 Themed Business Email Compromise Schemes

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 12 min read  
Related Products  
[![Advanced Threat Prevention icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced Threat Prevention](https://unit42.paloaltonetworks.com/product-category/advanced-threat-prevention/ "Advanced Threat Prevention")[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/product-category/advanced-url-filtering/ "Advanced URL Filtering")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Peter Renals](https://unit42.paloaltonetworks.com/author/peter-renals/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:May 7, 2020

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Business Email Compromise](https://unit42.paloaltonetworks.com/category/business-email-compromise/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [BEC](https://unit42.paloaltonetworks.com/tag/bec/)
  * [COVID](https://unit42.paloaltonetworks.com/tag/covid/)
  * [Law Enforcement](https://unit42.paloaltonetworks.com/tag/law-enforcement/)
  * [SilverTerrier](https://unit42.paloaltonetworks.com/tag/silverterrier/)
  * [Syndicate Orion](https://unit42.paloaltonetworks.com/tag/syndicate-orion/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/silverterrier-covid-19-themed-business-email-compromise/?pdf=download&lg=en&_wpnonce=279fa6c5e6 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/silverterrier-covid-19-themed-business-email-compromise/?pdf=print&lg=en&_wpnonce=279fa6c5e6 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=SilverTerrier:%20New%20COVID-19%20Themed%20Business%20Email%20Compromise%20Schemes&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fsilverterrier-covid-19-themed-business-email-compromise%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fsilverterrier-covid-19-themed-business-email-compromise%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fsilverterrier-covid-19-themed-business-email-compromise%2F&title=SilverTerrier:%20New%20COVID-19%20Themed%20Business%20Email%20Compromise%20Schemes "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fsilverterrier-covid-19-themed-business-email-compromise%2F&text=SilverTerrier:%20New%20COVID-19%20Themed%20Business%20Email%20Compromise%20Schemes "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fsilverterrier-covid-19-themed-business-email-compromise%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=SilverTerrier:%20New%20COVID-19%20Themed%20Business%20Email%20Compromise%20Schemes%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fsilverterrier-covid-19-themed-business-email-compromise%2F "Share in Mastodon")

## Executive Summary

Focusing on one of the most active subsets of the global threat landscape, Palo Alto Networks Unit 42 tracks Nigerian cyber criminals involved in Business Email Compromise (BEC) activities under the name [SilverTerrier](https://unit42.paloaltonetworks.com/silverterrier-2019-update/). Over the past 90 days (Jan. 30 - Apr. 30), we have observed three SilverTerrier actors/groups launch a series of 10 COVID-19 themed malware campaigns. These campaigns have produced over 170 phishing emails seen across our customer base. While broad in their targeting, these actors have exercised minimal restraint in terms of targeting organizations that are critical to COVID-19 response efforts. Specifically, we find it alarming that several of these campaigns recklessly included targets at government healthcare agencies, local and regional governments, large universities with medical programs/centers, regional utilities, medical publishing firms, and insurance companies across the United States, Australia, Canada, Italy, and the United Kingdom.

According to the recently released [annual report](https://pdf.ic3.gov/2019_IC3Report.pdf) from the Internet Crime Complaint Center (IC3), the Federal Bureau of Investigation (FBI) observed a record 23,775 BEC attacks in 2019. Significantly greater than all other categories of cybercrime over the same period, these attacks resulted in an estimated US$1.77 billion in global losses.

With the global impacts of COVID-19, an unprecedented number of corporations are expediating their cloud infrastructure migrations, all while transitioning to a largely remote workforce that is understandably interested in all topics related to the virus. Given this trend, it should come as no surprise that BEC actors are seizing opportunities to exploit the situation through tailored phishing campaigns related to COVID-19.

None of the malicious campaigns mentioned in this blog were successful in infecting their intended targets. Palo Alto Networks security service offerings (URL Filtering, WildFire, and Threat Prevention) detect and classify all samples and associated infrastructure as malicious.

### Actor 1

We identified the most pronounced activity as a series of eight campaigns that are either directly related, or within one to two degrees of separation, from a SilverTerrier actor that is well-known across the cybersecurity community. For the purposes of this blog, we will refer to this individual as Actor 1.

##### **Campaign 1**

The first campaign was launched on January 30, 2020 with variations of the email subject sent in both English and Indonesian. Attached to the email was a sample of Lokibot malware disguised as an Indonesian health department document. Upon infecting a victim, the malware was designed to call out to petroindonesia\[.\]co\[.\]id.
![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/05/word-image-2.png) Table 1. Indicators from the first campaign

##### **Campaign 2**

A little more than a month later, we observed a single email sent to a major utility provider in the United States. This message was crafted to appear as if it were an email that had been forwarded from the "UN," presumed to be the United Nations. Attached to the email was a Microsoft Excel spreadsheet containing text written in the Afrikaans language (Figure 1). Upon opening, the file leverages the CVE [2017-11882](https://nvd.nist.gov/vuln/detail/CVE-2017-11882) vulnerability to call out and download an executable called "dutchz.exe" from the domain uzoclouds\[.\]eu and subsequently attempts to connect to via SMTP to mailhostbox\[.\]com. Although Microsoft has released security updates for this vulnerability, it remains in common use amongst cyber criminals. In attributing this activity, the domain uzoclouds\[.\]eu stands out as being directly associated with Actor 1, and the Excel file itself was last edited by modexcomm which is a known alias for this actor.
![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/05/word-image-3.png) Figure 1. Content and translation of UPDATE!!!.xlsx ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/05/word-image-4.png) Table 2. Indicators from the second campaign

##### **Campaign 3**

On March 23, 2020 a third campaign was discovered with several phishing emails sent to an Australian health insurance provider. This time the subject and attachment were scoped to portray an order form for new face masks. Similar to the previous campaign, the attached RTF document leveraged the CVE 2017-11882 vulnerability to call out to both posqit\[.\]net and bit\[.\]ly, thus taking advantage of a URL shortening service to obscure one of the connections. Per the research and analysis [blog](https://www.cyren.com/blog/articles/covid-agenttesla-3481) by Cyren, this sample downloads and installs AgentTesla malware.
![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/05/word-image-5.png) Table 3. Indicators from the third campaign

##### **Campaign 4**

Beginning the next day (March 24) and continuing through April 7, 2020, a fourth, more complex, campaign was observed. This time, three different email accounts were used to send three different malicious attachments. Common amongst all of these phishing attempts was the same email subject relating to COVID-19 supplies. Noting that email subjects are not typically used as a basis for establishing correlation between phishing campaigns, we believe that in this case the uniqueness of the subject (to include identical capitalization and punctuation), combined with similar attachment names and malware families provides a sufficient pattern to suggest that these three events are related.

The first emails were sent to several recipients, including a university in the United States with a large medical program. Consistent with previous campaigns, the attachment was a Microsoft Office document that leveraged the CVE 2017-11882 vulnerability. More specifically, it was a protected Excel file with the blurred heading "Galaxy International Trading Limited" that upon being opened, called out to both mecharnise\[.\]ir and metadefenderinternationalsolutionfor\[.\]duckdns\[.\]org to download additional executables on victim machines.
[![COVID-19 BEC Malware Example](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/05/Figure-2.-Campaign-4-Email-Targeting-US-University-Sample-Products.xlsx.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/05/Figure-2.-Campaign-4-Email-Targeting-US-University-Sample-Products.xlsx.png) Figure 2. Campaign 4 Email Targeting US University - Sample Products.xlsx

Next, we saw a single phishing email sent to a Canadian health agency. Setting itself apart from previous samples, this attachment was in fact a sample of AgentTesla packaged as "Product\_Sample\_List.exe" inside a compressed RAR file. After infecting a potential victim, this file was configured to use SMTP for its command and control with coffiices\[.\]com.

Finally, the third set of emails were sent to several recipients, including an Australian energy company. Consistent with the previous email, this set once again included a sample of AgentTesla packaged as "Sample Product.exe" inside a compressed RAR file. Additionally, similar to the second campaign, this sample was configured to connect to an account at mailhostbox\[.\]com for command and control.
![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/05/word-image-7.png) Table 4. Indicators from the fourth campaign

##### **Linking Campaigns 1-4**

In examining the connection between Actor 1, Nigerian cybercrime, and these first four phishing campaigns, we found that when malware linkages from these campaigns and historical BEC activity were overlaid with insights afforded by a weakness in Lokibot malware ([Malbeacon](https://malbeacon.com/) data), several interesting connections emerged (Figure 2). While not definitive in attributing all of this activity to Actor 1, these connections chart a path originating with Actor 1's infrastructure, through the infrastructure for these new COVID-19 campaigns, and back to Nigeria.

At the top of our analysis, we start with four European Union (.eu) domains that are directly attributed to Actor 1's previously identified BEC activity. Solid lines connecting the domains and IP addresses are based on insights provided by the actor's employment of Lokibot malware, while dashed lines represent the existence of malware samples that connect to both domains. Following the link to hojokk\[.\]com, we discovered malware hosted in a folder called "MMC." While we lack insight into Actor 1's middle name, his first and last initial are coincidently "MC." Moreover, following additional connections to and from this domain, we discovered several links to Nigeria, as well as malware overlap with posqit\[.\]net, which we will discuss further in a subsequent campaign below.

Focusing on mecharnise\[.\]ir, we found malware overlaps with two of Actor 1's domains. Moreover, we discovered shared Lokibot malware connections to two specific Nigerian IP addresses that both overlap with petroindonesia\[.\]co\[.\]id.
[![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/05/Figure-3.-Infrastructure-connections-for-campaigns-1-4.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/05/Figure-3.-Infrastructure-connections-for-campaigns-1-4.png) Figure 3: Infrastructure connections for campaigns 1-4

##### **Campaign 5**

Using these connections as a starting point, we then began our analysis of campaign five, which began on March 26, 2020. Similar to the previous campaign, we noted multiple malware samples and sending accounts, to include spoofing a clinical research organization in the United States.

The first email was seen by a single customer and was packaged once again as a purchase order form for COVID-19-related products. An Excel document was attached and configured to exploit the CVE 2017-11882 vulnerability in order to download and run an executable file mapped to systemserverrootmapforfiletrn\[.\]duckdns\[.\]org. Similar to previous campaigns, the downloaded file then connected over SMTP to an account at mailhostbox\[.\]com. Additionally, it's worth noting that the Excel attachment was seen in a separate BEC style campaign the same day (see Figures 4. and 5.) and that the document also contained the blurred title of "Galaxy International Trading Limited," consistent with the fourth campaign. Since the exact same file was sent in multiple phishing campaigns using different themes on the same day, we can assert with greater confidence that these attacks are connected.
[![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/05/Figure-4.-Separate-BEC-Campaign-with-the-Same-Attachment.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/05/Figure-4.-Separate-BEC-Campaign-with-the-Same-Attachment.png) Figure 4. Separate BEC Campaign with the Same Attachment [![COVID-19 Malware Sample](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/05/Figure-5.-Campaign-5-Sample-Sent-from-Spoofed-US-Clinical-Research-Org.-PO-For-COVID-19-ProductS.xlsx.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/05/Figure-5.-Campaign-5-Sample-Sent-from-Spoofed-US-Clinical-Research-Org.-PO-For-COVID-19-ProductS.xlsx.png) Figure 5. Campaign 5 Sample Sent from Spoofed US Clinical Research Org. - PO For-COVID-19 ProductS.xlsx

On March 29, 2020, a second phishing email was sent to a government agency in the United States with the same subject and filename. However, this time the attachment was AgentTesla malware packaged as an executable file that, once again, connected to an account at mailhostbox\[.\]com for command and control. Furthermore, this email was sent from the domain reynoldsgh\[.\]com which maintains an active website that appears incomplete and is potentially fraudulent, with a Ghana phone number listed under contact information.

[![COVID-19 BEC Phishing Sample](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/05/Figure-6.-Screenshot-of-reynoldsgh.com_.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/05/Figure-6.-Screenshot-of-reynoldsgh.com_.png) Figure 6. Screenshot of reynoldsgh\[.\]com The third series of emails arrived on April 6, 2020. Sent to a medical publishing company in Europe and a government agency in the United States, this email also included a sample of AgentTelsa malware configured to use SMTP for communication with an account at mailhostbox\[.\]com.

![Indicators of BEC COVID-19 Campaigns](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/05/word-image-12.png) Table 5. Indicators from the fifth campaign

##### **Campaign 6**

Following an emerging trend of using Dynamic DNS services offered by DuckDNS, on March 30, 2020 we identified a single phishing email disguised as a vessel delay letter from a potentially spoofed shipping company in Singapore. A Word document was attached to the email with a CVE 2017-11882 exploit that called out to kungfrdyeducationalinvestment8agender\[.\]duckdns\[.\]org to download another document, and an executable file assessed to be Formbook malware, based on a report by [Infoblox](https://www.infoblox.com/wp-content/uploads/threat-intelligence-report-formbook-coronavirus-campaigns.pdf).
![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/05/word-image-13.png) Table 6. Indicators from the sixth campaign

#### **Dynamic DNS Clusters**

Deriving linkages from the connections used in campaigns four through six proved exceptionally challenging based on the function and anonymity afforded by dynamic DNS services. However, by pivoting through several layers of obfuscation, we identified three clusters of DuckDNS hosts with links to Nigeria. While difficult to attribute all of this activity directly to Actor 1, the malware overlap seen in the third campaign with mecharnise\[.\]ir , combined with malware packaging similarities (CVE-2017-11882) and a Nigerian nexus, all lead us to believe that this activity is likely related within one or two degrees of separation from Actor 1.

Starting with metadefenderinternationalsolutionfor\[.\]duckdns\[.\]org from the fourth campaign, we quickly found an initial cluster of five hosts that were all related based on an IP connection and their creation dates. Coincidently, this cluster included another host with a COVID-19-related name seen in the fifth campaign: systemserverrootmapforfiletrn\[.\]duckdns\[.\]org. Researching these hosts, we found several additional samples of malware packaged as Microsoft Word and Excel documents with the CVE-2017-11882 vulnerability and also found additional malware overlaps.
![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/05/word-image-14.png) Table 7. Dynamic DNS Cluster 1

Further analysis of the IP address connection revealed a second cluster of hosts linked to an additional 71 samples of malware with traditional BEC themes.
![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/05/word-image-15.png) Table 8: Dynamic DNS Cluster 2

Following the malware link between cluster 1 and 23\[.\]95\[.\]132\[.\]48, we discovered that this IP address provided command and control for over 200 samples of Lokibot malware. The vast majority of these samples were configured to call back to a dynamic DNS host in order to download an executable file, before calling out to the IP address for command and control. Pivoting from these samples, we identified a third cluster containing 48 hosts with consistent naming patterns. Interestingly, records show that many of these hosts were established within days of the second cluster, and while they point towards IP addresses in Vietnam, they were initially established using Nigerian infrastructure.
![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/05/word-image-16.png) Table 9. Dynamic DNS Cluster 3

Reviewing the list of hosts in cluster three, the following naming conventions stand out: chnes, engine, kung, russchine, shgshg, and tesco. However, most notably cluster three includes kungfrdyeducationalinvestment8agender\[.\]duckdns\[.\]org which we observed in the sixth campaign above.
![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/05/word-image-17.png) Figure 7. Infrastructure connections between campaigns

##### **Campaign 7**

A seventh campaign was launched spanning April 7th and 8th 2020, in which two samples of NanoCore RAT were packaged as compressed RAR files with a vaccine-related lure. These samples were sent to several organizations including a government health agency and two universities with medical programs in the United States, as well as a Canadian health insurer.
![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/05/word-image-18.png) Table 10. Indicators from the seventh campaign

Connecting this campaign to Actor 1, we found malicious activity originating from the domain ladbible\[.\]com dating back to mid-January. Tracing the earliest activity back to Nigerian origins, we also discovered that less than two weeks prior to this campaign, this domain was used to distribute a sample of Lokibot malware. That sample called back to two domains previously attributed to Actor 1 (sylvaclouds\[.\]eu and hokokk\[.\]com) and outlined in Figure 3 above.

##### **Campaign 8**

On April 8, 2020, we witnessed the most recent campaign by this actor. Distributed broadly, targets of this campaign included a government health agency, state infrastructure, and a health insurance company in the United States, in addition to a university and regional government in Italy, and various government institutions in Australia. Disguised as COVID-19 relief materials coming from a "Thai Medical Department," these phishing emails were delivered with one of two samples of Lokibot malware designed to call out to 185\[.\]126\[.\]202\[.\]111 for command and control. As seen in Figure 3 above, analysis performed on this IP address identified malware overlap with dynamic DNS clusters one and three.
![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/05/word-image-19.png) Table 11. Indicators from the eighth campaign

### Actor 2

Separate and distinct from the campaigns above, we identified a single campaign associated with the name of Alhaji. Between March 17th and 18th, 2020, two samples of Lokibot malware were sent to several organizations, including a government health agency in the United States. These samples called out academydea\[.\]com/alhaji/Panel/five/fre\[.\]php for command and control. Upon researching this domain, we discovered an additional 16 samples of malware used in the previous month. Further, leveraging insights from a vulnerability in Lokibot malware, we were able to trace this activity back to Nigerian IP addresses.
![Indicators of BEC Phishing Campaigns](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/05/word-image-20.png) Table 12. Indicators from Actor 2's campaign

### Actor 3

Between March 23rd and 24th, 2020, a SilverTerrier actor using the name Black Emeka launched a series of emails containing malicious attachments. Disguised as COVID-19 information, these emails originated from the domain welheadcontrol\[.\]com, which is registered to the actor. The attached malware samples use PowerShell to download malicious executable files from the domain goldenlion\[.\]sg, which resolves to an active website for Golden Lion Technology PTE LTD in Singapore. While likely not a coincidence, the website advertises Goldhofer equipment, while this actor is also the registered owner of the typo variant domain goldhhofer\[.\]com.
![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/05/word-image-21.png) Figure 8. Advertising for Goldhofer on goldlion\[.\]sg ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/05/word-image-22.png) Table 13. Indicators from Actor 2's campaign

## Conclusion

As 2020 progresses, the most prominent threat facing customers is commodity malware deployed in support of sophisticated BEC schemes. Given the global impacts of COVID-19, SilverTerrier actors have begun adapting their phishing campaigns and will likely continue to use COVID-19-themed emails to deliver commodity malware broadly in support of their objectives. In light of this trend, we encourage government agencies, healthcare and insurance organizations, public utilities, and universities with medical programs to apply extra scrutiny to COVID-19-related emails containing attachments. While organizations with appropriate spam filtering, proper system administration, and up-to-date Windows hosts have a much lower risk of infection, we further encourage administrators to validate installation of the Microsoft patch for CVE [2017-11882](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11882).

Additionally, Palo Alto Networks customers benefit from the following:

|---------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/05/word-image-23.png) | Cortex XDR protects endpoints from all malware, exploits and fileless attacks associated with SilverTerrier actors.                                                                                        |
| ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/05/word-image-24.png) | WildFire® cloud-based threat analysis service accurately identifies samples associated with these malware families.                                                                                        |
| ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/05/word-image-25.png) | Threat Prevention provides protection against the known client and server-side vulnerability exploits, malware, and command and control infrastructure used by these actors to include CVE 2017-11882      |
| ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/05/word-image-26.png) | URL Filtering identifies all phishing and malware domains associated with these actors and proactively flags new infrastructure associated with these actors before it is weaponized.                      |
| ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/05/word-image-27.png) | Users of AutoFocus™ contextual threat intelligence service can view malware associated with these attacks using the[SilverTerrier](https://autofocus.paloaltonetworks.com/#/tag/Unit42.SilverTerrier) tag. |

### Indicators of Compromise

#### **Malware Samples**

3335ebffd8b4ab739db99f68cd6d79caa39c1210c274bbe4166194cc26de4123

e365100468e9472518d1875796932a8085ab29f6bbfe3357928fa9cc6187628b

27d601ef1a2b340b6b644493a627064f60ad8a95271248e00f7bb54a59abb069

563b1c6252612d06b714bf29b9f53f7aade4c7ac6658b2d0c774a7e244ea83da

0ae2aaeb2938cf4c777be4aa192e4994020609f5640add8e7296de9ff34eb227

4b8b49bdfa435d0faba2e3964b04e20bbfc86aa4ffc3c3b8e1449894892f125b

589a1900b210826e97ec8da3c5c40f707963146e934393eb15e1b07a1398912c

7f661c6f5ebba3eca82e1dbf1a96e27f2503da405093464538d90dc113a7b439

f7183d3a992ead2bf194ac46b1f6f70ad9e30bfd5b6065ffbd96a3529c311725

83457e2b8f9209ec1c987b1a0bee65140cc41d1d59ed38f1d1ad160ea0d1d13c

b58e386928543a807cb5ad69daca31bf5140d8311768a518a824139edde0176f

c5c43b340957830f5d7484ce06f9de0ef593d88f3d48c09cd2150e670661f672

f7b9219f81772e928ab0fbd0becbcf10ca3792ce211bb4a7fa68b41050bdb220

241f09feda09dc33b86e23d317bc2425f4d43b91221815caa5eb055a9a97be74

31d2ef10cad7d68a8627d7cbc8e85f1b118848cefc27f866fcd43b23f8b9cff3

7b2512d06723cc29f80ae8c8d6df141f27bc9d962ae76b5651b84d7be4379bba

aff38fe42c8bdafcd74702d6e9dfeb00fb50dba4193519cc6a152ae714b3b20c

8f56fb41ee706673c706985b70ad46f7563d9aee4ca50795d069ebf9dc55e365

da26ba1e13ce4702bd5154789ce1a699ba206c12021d9823380febd795f5b002

1ee6646e0ea9ceb6fa1721f809bd3cdaeb38c6b2bdd7171b340097c237527568

d731fb3fcc6ecd266251408a282ef4409eac94ce25cecadbfcb2df08e7ca7693

d80a440755dc15803db459b15b991d1abe81054f0942d054d965a578b92917b7

8037a8e12e8cacdaca24b993ffdbd8cdc63ec29dd78eee136083fa09049dbf0c

#### **Domains:**

academydea\[.\]com

coffiices\[.\]com

goldenlion\[.\]sg

ladbible\[.\]com

mecharnise\[.\]ir

mikeservers\[.\]eu

modcloudserver\[.\]eu

petroindonesia\[.\]co\[.\]id

posqit\[.\]net

reynoldsgh\[.\]com

sylvaclouds.eu

uzoclouds\[.\]eu

welheadcontrol\[.\]com

#### **Dynamic DNS Hosts:**

12kungwsdyducationaldeveloperinvestmenty\[.\]duckdns\[.\]org

6uniteddefenceforstdygorvermentsocialeme\[.\]duckdns\[.\]org

americanmicrosoftclouddepartment\[.\]duckdns\[.\]org

antipiracydetectorganisationforwsdy3film\[.\]duckdns\[.\]org

bbchenkotsdywoolandpappercompanybnhs5\[.\]duckdns\[.\]org

chinoex2onlineantibullyandgeneralxpstdy5\[.\]duckdns\[.\]org

chnes9wealthandstdyorganisationsumit\[.\]duckdns\[.\]org

chneswealstdy8thandorganisationjokbo\[.\]duckdns\[.\]org

chneswealthandorganisationstdy7joppl\[.\]duckdns\[.\]org

chneswsdy13wealthandmoduleorganisationrn\[.\]duckdns\[.\]org

chneswsdy8wealthandorganisationjokbo\[.\]duckdns\[.\]org

chnfrndsecurityandgorvermentstdy1socialf\[.\]duckdns\[.\]org

chnfrndsub1inteligentangencysndy4project\[.\]duckdns\[.\]org

chnfrndtsdysecurityandgorvermentsocialjf\[.\]duckdns\[.\]org

chnfrndwsdy1securityandgorvermentsocialf\[.\]duckdns\[.\]org

cloudfilesharingdomainurllinksys\[.\]duckdns\[.\]org

crimedetectivefor1stdygorvermentndsocial\[.\]duckdns\[.\]org

empowermentorganisationstday1government\[.\]duckdns\[.\]org

engin3worldstdydevelopmentandtechnology\[.\]duckdns\[.\]org

engintsdy3worlddevelopmentandtechnology\[.\]duckdns\[.\]org

fileexchangeserverprotocolsystemintergra\[.\]duckdns\[.\]org

filegotosecureothers\[.\]duckdns\[.\]org

frndgreen1frdycreamcostmeticsladiesshop\[.\]duckdns\[.\]org

frndgreen3creamwsdycostmeticsbabystored\[.\]duckdns\[.\]org

globaltransfersecurefilethroughcloud\[.\]duckdns\[.\]org

green9wsdyelectronicsandkitchenappliance\[.\]duckdns\[.\]org

investmenteducationkungykmtsdy8agender\[.\]duckdns\[.\]org

kung11ducationalstdydeveloperinvestmenty\[.\]duckdns\[.\]org

kung13eduationalstdydeveloperinvestmenty\[.\]duckdns\[.\]org

kungeducationalinvestment8tusdyagender\[.\]duckdns\[.\]org

kungfrdyeducationalinvestment8agender\[.\]duckdns\[.\]org

kungglobalinvestmenteductgpmstdy8addres\[.\]duckdns\[.\]org

kungglobalinvestmentjpjeductaddres5stdy\[.\]duckdns\[.\]org

kungglobalinvestmentjpjwsdy6eductaddres\[.\]duckdns\[.\]org

kungstdy7globalinvestmentjmpeductaddres\[.\]duckdns\[.\]org

kungwsdy7globalinvestmentjmpeductaddres\[.\]duckdns\[.\]org

livevideoremoteconference\[.\]duckdns\[.\]org

mastervisacloudesystemprtomicrosftwareus\[.\]duckdns\[.\]org

msofficeinternatiinalfilecloudtransfer\[.\]duckdns\[.\]org

msofficewordfiletransfertotheadmintrue\[.\]duckdns\[.\]org

office365securefilegatewaytransfer\[.\]duckdns\[.\]org

omentradinginternationalprivateltd\[.\]duckdns\[.\]org

prodigtsdy5organizationalcompanygroupin\[.\]duckdns\[.\]org

russchine2specialstdy1plumbingmaterialsv\[.\]duckdns\[.\]org

russchine2specialstdy2plumbingmaterialgh\[.\]duckdns\[.\]org

russchine2wsdy1specialplumbingmaterialsv\[.\]duckdns\[.\]org

russchine2wsdyspecial6plumbingjkmaterial\[.\]duckdns\[.\]org

shgshg13nationalwsdyobjindustrialatempt\[.\]duckdns\[.\]org

shgshg9nationalobjwsdyindustrialgoogler\[.\]duckdns\[.\]org

shgshgnationalindustrialwsdy8googleklm\[.\]duckdns\[.\]org

shgshgnationalobjindustrialstdy10atempt\[.\]duckdns\[.\]org

shgshgnstdy7ationalindustrialgoogleklm\[.\]duckdns\[.\]org

shgshgstdy9nationalobjindustrialgoogle\[.\]duckdns\[.\]org

silentexploitfileexchangerzeroday\[.\]duckdns\[.\]org

tescogroseryand1wsdayelectronicstorehome\[.\]duckdns\[.\]org

tescohomegroseryandelectronicstday2store\[.\]duckdns\[.\]org

tescostday1groseryandelectronicstorehome\[.\]duckdns\[.\]org

webxpostdytechnologyhardsoftware5buyers\[.\]duckdns\[.\]org

wewewewewesesesesasbacwederffggffddsss\[.\]duckdns\[.\]org

windowsdefenderwithfiewallprotocolsecure\[.\]duckdns\[.\]org

windowsfirewallprotcolsecuritysystem\[.\]duckdns\[.\]org

worldengindevelopnw7stdymenttechnology\[.\]duckdns\[.\]org

#### **IP Addresses:**

23\[.\]95\[.\]132\[.\]48

185\[.\]126\[.\]202\[.\]111

Palo Alto Networks has shared our findings, including file samples and indicators of compromise, in this report with our fellow Cyber Threat Alliance members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. For more information on the Cyber Threat Alliance, visit [www.cyberthreatalliance.org](https://www.cyberthreatalliance.org/).

Back to top

### Tags

* [BEC](https://unit42.paloaltonetworks.com/tag/bec/ "BEC")
* [COVID](https://unit42.paloaltonetworks.com/tag/covid/ "COVID")
* [Law Enforcement](https://unit42.paloaltonetworks.com/tag/law-enforcement/ "Law Enforcement")
* [SilverTerrier](https://unit42.paloaltonetworks.com/tag/silverterrier/ "SilverTerrier")
* [Syndicate Orion](https://unit42.paloaltonetworks.com/tag/syndicate-orion/ "Syndicate Orion")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: COVID-19: Cloud Threat Landscape](https://unit42.paloaltonetworks.com/covid-19-cloud-threat-landscape/ "COVID-19: Cloud Threat Landscape")

### Table of Contents

* 

### Related Articles

* [Operation Delilah: Unit 42 Helps INTERPOL Identify Nigerian Business Email Compromise Actor](https://unit42.paloaltonetworks.com/operation-delilah-business-email-compromise-actor/ "article - table of contents")
* [Operation Falcon II: Unit 42 Helps INTERPOL Identify Nigerian Business Email Compromise Ring Members](https://unit42.paloaltonetworks.com/operation-falcon-ii-silverterrier-nigerian-bec/ "article - table of contents")
* [SilverTerrier -- Nigerian Business Email Compromise](https://unit42.paloaltonetworks.com/silverterrier-nigerian-business-email-compromise/ "article - table of contents")

## Related Business Email Compromise Resources

![Pictorial representation of a group of individuals discussing an idea with a whiteboard.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/02_Listicle_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) February 3, 2026 [#### Why Smart People Fall For Phishing Attacks](https://unit42.paloaltonetworks.com/psychology-of-phishing/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/psychology-of-phishing/ "Why Smart People Fall For Phishing Attacks")  
  ![Pictorial representation of a IUAM ClickFix generator. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen, indicating malware.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/10/03_Malware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) October 8, 2025 [#### The ClickFix Factory: First Exposure of IUAM ClickFix Generator](https://unit42.paloaltonetworks.com/clickfix-generator-first-of-its-kind/)

* [Bash](https://unit42.paloaltonetworks.com/tag/bash/ "bash")

* [ClickFix](https://unit42.paloaltonetworks.com/tag/clickfix/ "ClickFix")

* [Phishing Kit](https://unit42.paloaltonetworks.com/tag/phishing-kit/ "Phishing Kit")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/clickfix-generator-first-of-its-kind/ "The ClickFix Factory: First Exposure of IUAM ClickFix Generator")  
  ![Pictorial representation of phishing bait using AI. A luminous cube labeled "AI" centrally placed on a futuristic circuit board landscape with glowing blue lights and connections.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/03_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 19, 2025 [#### Fashionable Phishing Bait: GenAI on the Hook](https://unit42.paloaltonetworks.com/genai-phishing-bait/)

* [GenAI](https://unit42.paloaltonetworks.com/tag/genai/ "GenAI")

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/genai-phishing-bait/ "Fashionable Phishing Bait: GenAI on the Hook")  
  ![Pictorial representation of social engineering. Digital illustration of four human profiles connected by glowing neural network lines against a dark background, symbolizing connectivity and technology.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/cover-1920x900-no-blades-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-report-white-1.svg)Trend Reports](https://unit42.paloaltonetworks.com/category/trend-reports/) July 30, 2025 [#### 2025 Unit 42 Global Incident Response Report: Social Engineering Edition](https://unit42.paloaltonetworks.com/2025-unit-42-global-incident-response-report-social-engineering-edition/)

* [Agent Serpens](https://unit42.paloaltonetworks.com/tag/agent-serpens/ "Agent Serpens")

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ClickFix](https://unit42.paloaltonetworks.com/tag/clickfix/ "ClickFix")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/2025-unit-42-global-incident-response-report-social-engineering-edition/ "2025 Unit 42 Global Incident Response Report: Social Engineering Edition")  
  ![Pictorial representation of homograph attacks. 3D illustration of an open laptop displaying an envelope icon on the screen, accompanied by a smartphone and tablet, all set against a dark background with neon lighting.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/01_Business_email_compromise_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 25, 2025 [#### The Ηоmоgraph Illusion: Not Everything Is As It Seems](https://unit42.paloaltonetworks.com/homograph-attacks/)

* [GenAI](https://unit42.paloaltonetworks.com/tag/genai/ "GenAI")

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/homograph-attacks/ "The Ηоmоgraph Illusion: Not Everything Is As It Seems")  
  ![Pictorial representation of the ransomware landscape. Digital artwork of a disintegrating U.S. dollar bill with pixelated effects on a cyber-inspired background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/04/05_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-report-white-1.svg)Trend Reports](https://unit42.paloaltonetworks.com/category/trend-reports/) April 23, 2025 [#### Extortion and Ransomware Trends January-March 2025](https://unit42.paloaltonetworks.com/2025-ransomware-extortion-trends/)

* [BianLian](https://unit42.paloaltonetworks.com/tag/bianlian/ "BianLian")

* [Akira ransomware](https://unit42.paloaltonetworks.com/tag/akira-ransomware/ "Akira ransomware")

* [Muddled Libra](https://unit42.paloaltonetworks.com/tag/muddled-libra/ "Muddled Libra")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/2025-ransomware-extortion-trends/ "Extortion and Ransomware Trends January-March 2025")  
  ![Pictorial representation of a QR code phishing campaign. Digital artwork of a futuristic, glowing shield disintegrating into small particles, set against a dark blue, speckled background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/03/09_Business_email_compromise_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) April 1, 2025 [#### Evolution of Sophisticated Phishing Tactics: The QR Code Phenomenon](https://unit42.paloaltonetworks.com/qr-code-phishing/)

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")

* [Social engineering](https://unit42.paloaltonetworks.com/tag/social-engineering/ "social engineering")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/qr-code-phishing/ "Evolution of Sophisticated Phishing Tactics: The QR Code Phenomenon")  
  ![An Asian woman examining data on multiple computer screens in a high-tech digital environment, surrounded by visual representations of data and code. Lens flare is prominent across the image.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/02/07_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) February 28, 2025 [#### JavaGhost's Persistent Phishing Attacks From the Cloud](https://unit42.paloaltonetworks.com/javaghost-cloud-phishing/)

* [AWS](https://unit42.paloaltonetworks.com/tag/aws/ "AWS")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/javaghost-cloud-phishing/ "JavaGhost’s Persistent Phishing Attacks From the Cloud")  
  ![Pictorial representation of a European phishing campaign. A digital artwork depicting a glowing, futuristic shield disintegrating into small fragments against a shimmering blue background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/12/09_Business_email_compromise_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) December 18, 2024 [#### Effective Phishing Campaign Targeting European Companies and Organizations](https://unit42.paloaltonetworks.com/european-phishing-campaign/)

* [EMEA](https://unit42.paloaltonetworks.com/tag/emea/ "EMEA")

* [Manufacturing](https://unit42.paloaltonetworks.com/tag/manufacturing/ "Manufacturing")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/european-phishing-campaign/ "Effective Phishing Campaign Targeting European Companies and Organizations")  
  ![A pictorial representation of a campaign like BeaverTail. Digital globe with interconnected network lines and data streams on a futuristic interface, symbolizing global connectivity and information technology advancements.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/01_Nation-State-cyberattacks_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) November 14, 2024 [#### Fake North Korean IT Worker Linked to BeaverTail Video Conference App Phishing Attack](https://unit42.paloaltonetworks.com/fake-north-korean-it-worker-activity-cluster/)

* [North Korea](https://unit42.paloaltonetworks.com/tag/north-korea/ "North Korea")

* [Lazarus](https://unit42.paloaltonetworks.com/tag/lazarus/ "Lazarus")

* [BeaverTail](https://unit42.paloaltonetworks.com/tag/beavertail/ "BeaverTail")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/fake-north-korean-it-worker-activity-cluster/ "Fake North Korean IT Worker Linked to BeaverTail Video Conference App Phishing Attack")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
