W2KM_URSNIF.BYY Trojan Downloader Email Campaign
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
The attachment is a password protected macro enabled Word document which delivers the trojan downloader named :
- W2KM_URSNIF.BYY (TrendMicro)
- TrojanDownloader:O97M/Donoff (Microsoft)
- Trojan-Downloader.MSWord.Agent.ahj (Kaspersky)
When a computer becomes infected with the trojan downloader it installs other malware on the user's PC.
The subject line of the message includes the recipient's name.
The message within the body of the email uses social engineering techniques to encourage the user to open the attachment and appears in the following format:
Good day to you, [recipient’s name]!
I am disturbing you for a very critical occasion. Allhough we are not familiar, but I have large ammount of information about you. The matter is that, most probably by mistake, the information of your account has been sent to me.
For instance, your address is:
[recipient’s postal address]
I am a lawful citizen, so I decided to private data may have been hacked. I pinned the file - Curtis.dot that was sent to me, that you could view what data has become accessible for deceivers. File password is - 9013
Best wishes,
[Changing Name]
Remediation steps
Last edited: 17 February 2020 11:41 am