MintsLoader via PEC: False Payment Reminders to Spread Malware

MintsLoader via PEC: False Payment Reminders to Spread Malware
CERT-AGID identified and disrupted a new MintsLoader campaign that abused compromised PEC mailboxes to send convincing fake invoice-payment messages to other certified email addresses. The attack chain delivered a ZIP file containing HTML, JavaScript, PowerShell, and MintsLoader components, with rotating infrastructure and DGA-based domains leading to final payloads such as RATs and stealers. #CERT-AGID #MintsLoader #PEC

Keypoints

  • CERT-AGID detected a new MintsLoader campaign using compromised PEC accounts to send malicious messages.
  • The emails impersonated invoice/payment reminders and used credible language to pressure recipients into opening the attachment.
  • The attachment was a ZIP archive that led to an HTML file, which then fetched JavaScript and executed further stages through PowerShell.
  • The infection chain culminated in MintsLoader, used to download and launch additional malware on the victim system.
  • The infrastructure used to retrieve payloads changed frequently and included DGA-based domains.
  • Domains referenced in the campaign were initially inactive and became operational later, matching patterns seen in previous MintsLoader activity.
  • CERT-AGID coordinated mitigation with PEC providers and shared relevant IoCs through its IoC feed.

MITRE Techniques

  • [T1566.001] Spearphishing Attachment – The attackers sent fraudulent PEC messages with a ZIP attachment to lure victims into opening it (‘false reminders for unpaid invoices’ with an attached archive).
  • [T1204.002] User Execution: Malicious File – The infection required the recipient to open the ZIP/HTML file to trigger the next stage (‘the goal is to convince the recipient to open the ZIP archive attached to the message’).
  • [T1059.007] JavaScript – The HTML file downloaded and executed JavaScript as part of the infection chain (‘the HTML file contacts the infrastructure and downloads a JavaScript file’).
  • [T1059.001] PowerShell – The JavaScript launched additional stages using PowerShell on Windows systems (‘the chain leads to execution … also based on PowerShell’).
  • [T1105] Ingress Tool Transfer – The attacker-controlled infrastructure delivered additional payloads to the victim machine (‘downloads a file JavaScript’ and MintsLoader to ‘download and start other malware’).
  • [T1568.002] Domain Generation Algorithms – The campaign used DGA-based domains to rotate retrieval infrastructure (‘make use of techniques DGA (Domain Generation Algorithm)’).
  • [T1027] Obfuscated Files or Information – The staged delivery through ZIP, HTML, JavaScript, and PowerShell obscured the final payload and its delivery path (‘PEC → ZIP archive → HTML file → JavaScript → PowerShell → MintsLoader’).

Indicators of Compromise

  • [Email subject lines ] fake invoice-payment lure used in the campaign – “Fattura non pagata – richiesta immediato riscontro”, “Sollecito pagamento fattura scaduta”, and other changing subjects
  • [File types / attachment chain ] malicious delivery chain in the message attachment – ZIP archive, HTML file, JavaScript file, and PowerShell execution
  • [Domains / URLs ] infrastructure used to fetch payloads, including DGA-based and later-activated domains – DGA-generated domains, attacker infrastructure URLs, and other rotating addresses
  • [Timing / campaign metadata ] campaign timing indicators from file metadata and message delivery – Monday 21 metadata, 23 September 21:50 delivery, and activation on 24 September morning


Read more: https://cert-agid.gov.it/news/mintsloader-via-pec-falsi-solleciti-di-pagamento-per-diffondere-malware/