Hackers spoofing US postal service to trap victims

US postal service
(Image credit: Pexels)

After making the rounds in Europe, a new phishing campaign has arrived in the US and the attackers behind it are impersonating the US postal system with the aim of infecting users' computers with a banking trojan according to new research from Proofpoint.

In November, researchers from the cybersecurity firm observed thousands of emails trying to deploy malicious Microsoft Word attachments in the US. These emails impersonated messages from the US postal service as part of a campaign to infect computers with the IcedID banking trojan.

IcedID was first discovered by IBM's X-Force Research division and the banking Trojan typically targets banks, payment card providers and financial institutions in an effort to steal user credentials.

However, the campaign discovered by Proofpoint is not targeting financial companies and is going after businesses in the healthcare industry instead. The phishing emails used in the campaign contain a malicious Word document that when opened, triggers a Microsoft Office macro that launches a PowerShell script to download and install IcedID onto a user's computer.

Phishing campaign

The US is the latest target of the campaign after Proofpoint observed the same threat actor targeting businesses in Germany by impersonating the German Federal Ministry of France. The attacker behind the campaign also employed the commercially available penetration testing tool, Cobalt Strike to deploy their malicious payloads.

To track down the origin of the malware, researchers at the firm analyzed over 5bn email messages, millions of social media posts and more than 250m malicious samples daily.

Proofpoint analyzed a number of characteristics including infrastructure, lure styles and macro code to identify and analyze the campaign's activity in the US. The firm found that the actions were not consistent with existing threat actors which suggests that a new group is likely behind the campaign.

Threat intelligence lead at Proofpoint, Christopher Dawson provided further details on the group and its malicious activities, saying:

"Although these campaigns are small in volume, currently, they are significant for their abuse of trusted brands, including government agencies, and for their relatively rapid expansion across multiple geographies. To date, the group appears to have targeted organizations in Germany, Italy, and, most recently, the United States, delivering geotargeted payloads with lures in local languages. We will be watching this new actor closely, given their apparent global aspirations, well-crafted social engineering, and steadily increasing scale."

  • Protect your devices from the latest cyber threats with the best antivirus software

Via TechRepublic

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
An American flag flying outside the US Capitol building against a blue sky
The FCC is creating a security council to bolster US defenses against cyberattacks
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
Ransomware
Microsoft uncovers sleuthy new XCSSET MacOS malware campaign
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Meta warns of worrying security flaw hitting open source type software
Hand holding smartphone and scan fingerprint biometric identity for unlock her mobile phone
Biometrics add another layer of security to passwordless authentication
Data leak
Hacked Tata Technologies data leaked by ransomware gang
Latest in News
Google Gemini Flash 2.0 Images
I tried Gemini's new AI image generation tool - here are 5 ways to get the best art from Google's Flash 2.0
An image of the Samsung Galaxy S25 Ultra from a hands-on event
Samsung Galaxy S26 Ultra could resurrect an intriguing camera feature
Eurocom Raptor X18
At $15,000, this massive 256GB RAM laptop makes Apple's MacBook Pro look affordable, tiny and very, very slow
Cristin Milioti in Black Mirror season 7
Netflix launches trailer for Black Mirror season 7, giving us a look at its first-ever sequel episode and an unexpected returning character
A graphic of the PC Gaming Show
Get ready for a bounty of PC games on June 8, as the PC Gaming show is back
A close up of The Daily podcast from Pocket Casts' web page
‘Podcasting shouldn’t be locked behind walled gardens’: Pocket Casts slams Spotify and makes its web player free to all