Thursday 27 June 2019, Poradnik bezpieczeństwa

Cybercriminals are impersonating Play network – fake invoices

Lost24

A new spam campaign has been launched and its targeting Play customers. The content of the e-mail is inconspicuous, there is only information on sending the invoice, which is included in the attachment, along with invoice number and the date of the issue, as well as client’s ID.


The content of the e-mail:


Play for companies


Good morning,
we send the invoice, which you will find in the attachment. Below we present a summary of it.

Invoice number: F / 10407696/06/19
Date of issue: 18/06/2019
Customer account number: 13414991

Thank you for using our services,
Play team


According to AVLAB, depending on the version of the campaign, the names of the attachments are different, it’s either dokument_92028.tar, dokument_76680.tar or dokument_52012.tar.
TAR archive in the attachment contains malicious software and file icon does not even slightly resemble the one associated with application that opens the regular invoices.