Phishing campaign against clients of several banks in Serbia

12. December 2019

A very convincing phishing campaign is under way against clients of several banks doing business in the Republic of Serbia. The phishing email seemingly sent out on behalf of several banks and appearing to be arriving from a legitimate domain, contains a notification on foreign exchange inflow and a malicious .pdf zip file attachment, activating a malicious code in the background. The malicous attachment is very sophisticated and has been recognized only by a few anitvirus softwares. For more details, please visit:

https://www.virustotal.com/gui/file/5b0fba8021987e7da274b48189791da7b86f8a07aa7d0fcf7698420cf9f6ad77/detection

https://www.virustotal.com/gui/file/66b8f8503abbf511784d87c4801cb1d73a67f7ca09b0fbf17519df3632a4edff/detection

Based on the available information, we notify the public that these emails are not being sent from the banks' servers.

The National CERT urges all bank clients who receive silimar emails to delete them right away and, under any circumstances, not to open the attachment.

The website www.cert.rs uses cookies for improvement of user experience and website functionality. By continuing to browse this website, you agree to the use of cookies.

Details