HC3 TLP White Sector Alert: Secure Message/Evernote-Themed Phishing Campaign – August 10, 2022

Executive Summary

HC3 has been made aware of a malspam campaign that is currently targeting various healthcare providers. The campaign has a subject of “(Victim Organization) (Date) Business Review” and utlizes a Secure Message theme. Inside of the email is a malicious link which lures the recipient to a Victim Organization themed Evernote site. On the site is an HTML download which has been identified as a malicious phishing Trojan. The file contains JavaScript which renders an Adobe and Microsoft themed page that attempts to harvest Outlook, IONOS, AOL, or other credentials. This campaign may have leveraged business email compromises (BECs) of HPH-related and possibly non-HPH entities.

Report

The campaign has a subject of “(Victim Organization) (Date) Business Review” and utlizes a Secure Message theme.

View the detailed report below.

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

National Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272