Security News > 2020 > December > Massive Subway UK phishing attack is pushing TrickBot malware
A massive phishing campaign pretending to be a Subway order confirmation is underway distributing the notorious TrickBot malware.
TrickBot is a trojan malware infection commonly distributed through phishing campaigns or installed by other malware.
What is concerning about these phishing emails is that they include the user's first name, and some users are reporting they are being sent to emails only used for Subway.
This attack may indicate a data breach at Subway UK that allowed the threat actors to gain access to customer's names and email addresses.
The Subway phishing emails are using email subjects such as "Your order is being processed" and "We've received your order," and state that it is from Subcard, as shown below.
News URL
Related news
- Astaroth Banking Malware Resurfaces in Brazil via Spear-Phishing Attack (source)
- New Brazilian-Linked SambaSpy Malware Targets Italian Users via Phishing Emails (source)
- Hackers deploy AI-written malware in targeted attacks (source)
- N. Korean Hackers Deploy New KLogEXE and FPSpy Malware in Targeted Attacks (source)
- New RomCom malware variant 'SnipBot' spotted in data theft attacks (source)
- Australian Organisations Targeted by Phishing Attacks Disguised as Atlassian (source)
- Free Sniper Dz Phishing Tools Fuel 140,000+ Cyber Attacks Targeting User Credentials (source)
- DOJ, Microsoft seize 107 domains used in Russia's Star Blizzard phishing attacks (source)
- GitHub, Telegram Bots, and ASCII QR Codes Abused in New Wave of Phishing Attacks (source)
- 99% of UK Businesses Faced Cyber Attacks in the Last Year (source)