GUILDMA

GUILDMAGuildma

Description

The campaign spreads via phishing emails posing as invoices, tax reports, invitations and similar types of messages containing a ZIP archive attachment with a malicious LNK file. When a user opens the malicious LNK file, it abuses the Windows Management Instrumentation Command-line tool and silently downloads a malicious XSL file. The XSL file downloads all of Guildma’s modules and executes a first stage loader, which loads the rest of the modules. The malware is then active and waits for commands from the C&C server and/or specific user interactions, such as opening a webpage of one of the targeted banks.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
LIGMA
Software
GammA
Software
Sigma Ransomware
Software
Gomme
Software
Prikormka
Software
Client Maximus
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.