This article looks at three real-life attacks attempted via corporate email, all of which were detected and stopped by Group-IB's Business Email Protection (formerly known as Group-IB Atmosphere). The attacks serve as a good example of how threat actors skillfully exploit weaknesses in the current approach to email security. In this regard, properly built corporate email security is obviously the first line of cyber defense for organizations.
Group-IB's Business Email Protection identified the payload and attributed the threat to the group Silence. From 2016, the group attacked financial organizations mainly in Russia, but in 2018 it expanded its geography and started attacking financial organizations worldwide. The Silence APT group is now thought to have joined a RaaS program.
This is what the file structure looked like in Group-IB's Business Email Protection: