Popular with online criminals, last week has seen a series of email scams going directly for the money jar.
Leveraging major accounting software brands that are popular with the SMB segment – like MYOB, Xero– the cybercrime networks may be chasing smaller businesses who don’t have a high security or an IT team to help defend against scams.
MailGuard blocked two email scams throughout the day purporting to be from accounting software mainstays MYOB and Xero.
The MYOB scam claimed to be sending recipients a supply order for signature, with a DocuSign link to a malicious .ZIP download. We received one of those last week.
With the subject ‘Your MYOB supply order’ the email was sent from randomized names ‘via DocuSign’ with a reply to address of the random name, for example, David(dot)Conlan @ myob.com.
The Xero attack was delivered at the same time as the MYOB scam and masqueraded as an invoice for your Xero subscription sent from ‘Xero Billing Notifications’ with a subject that reads ‘Your Xero Invoice INV-1816674’ in the example below. We receive one of these as well. Again, the link to ‘View your bill:’ leads to a malicious .ZIP payload.
This morning, the MailGuard team have blocked a brand-new scam pretending to be from an accounting practice that links to a fake tax return link with another malicious payload, titled ‘Tax return for [name].’
These emails are being sent from a compromised MailChimp account so the sending addresses are unique to each message.
The link is to a benign .docx file hosted on MailChimp, however, the .docx file contains 2 x OLE objects, both of which are CDF documents and can be opened in Microsoft Word or Excel.
The CDF documents themselves contain malicious macros, which are presumed at this stage to download a remote executable.
Finance departments that regularly deal with payments or accounting practices need to be extra cautious what they click this week. Read the full story here