Story image

New year rings in scams in the guise of Suncorp, MYOB, and ASIC emails

08 Jan 2018

MailGuard detected an email scam today using fake ‘Suncorp’ branding.

Suncorp is an Australian finance, insurance, and banking corporation based in Queensland.

The email was detected by MailGuard this morning and is currently being sent out in large numbers.

The message shows the sender addresses ‘SunCorp Insurance’ or ‘Health Insurance’, but the emails actually originate from a compromised MailChimp account.

The email asks the recipient to download ‘insurance documents’ and has a link pointing to an archived JavaScript file.

MailGuard reports that JavaScript files used in scams of this sort can contain malware such as Trojans, keystroke loggers and ransomware.

MailGuard advises users to be cautious and check your inbox to make sure you are not targeted by this scam.

Email scammers have already been actively targeting Australian email users, with MailGuard detecting one scam using MYOB branding and one using the Australian Securities and Investments Commission (ASIC) branding four days ago.

The MYOB message urges the recipient to click on a ‘view invoice’ link, which points to a file archive on a compromised SharePoint account.

The archive file contains malicious javascript malware.

Meanwhile, the ASIC email scam has a .doc attachment which contains malicious macro code.

Although the message purports to be from ASIC, the sender URL is actually ‘asicsau[dot]com’, a new URL registered on January 3 in China.

Cybercriminals use .doc macros in attachments like the one on this email to install malware on victim’s computers.

Macros run in the background when .doc files are opened and can be used to download trojans, spyware and viruses. 

Industrial control component vulnerabilities up 30%
Positive Technologies says exploitation of these vulnerabilities could disturb operations by disrupting command transfer between components.
McAfee announces Google Cloud Platform support
McAfee MVISION Cloud now integrates with GCP Cloud SCC to help security professionals gain visibility and control over their cloud resources.
WatchGuard announces A/NZ partners awards
Four Australian companies were named partner award winners at the WatchGuard conference in Vietnam.
Telstra’s 2019 cybersecurity report
Cybersecurity remains a top business priority as the estimated number of undetected security breaches grows.
Why AI and behaviour analytics should be essential to enterprises
Cyber threats continue to increase in number and severity, prompting cybersecurity experts to seek new ways to stop malicious actors.
Scammers targeting more countries in sextortion scam - ESET
The attacker in the email claims they have hacked the intended victim's device, and have recorded the person while watching pornographic content.
Cryptojacking and failure to patch still major threats - Ixia
Compromised enterprise networks from unpatched vulnerabilities and bad security hygiene continued to be fertile ground for hackers in 2018.
Why cybersecurity remains a top business priority
One in two Australian businesses estimated that they will receive fines for being in breach of new legislation.