Summary
Wapack Labs observed malicious email trending on CTAC which detected an uptick in Darwish Trading Company (DTC) spoofing. Hackers pretend to be from this Qatari company as it has a wide range of business activities to include servicing the oil and gas sector. During 29 March 2019 – 3 April 2019, these samples were seen delivering Lokibot and PonyLoader malware.
Details
Figure 1. Malicious .doc attachment in an email spoofing Darwish Trading Company
The Darwish Trading Company (DTC) has a w