National Cyber Security Centre (NCSC) in Switzerland has issued a new alert based on a new scheme from hackers and scammers that weaponizes the postal service. The scam involves a physical piece of mail arriving at a target's door, urging them to download an app.
The app, which can be downloaded via a QR code displayed on the mailer, is actually malware disguised as a legitimate app that can steal data from the user's device.
https://www.ncsc.admin.ch/ncsc/en/home/aktuell/im-fokus/2024/2024-meteosuisse.html
Microsoft just the other week reported more than 15,000 messages with malicious QR codes targeting the education sector had been sent every day over the past year
https://www.theregister.com/2024/10/13/schools_nationstate_attacks_ransomware/
The fake app, when downloaded, installs a "variant of the Coper trojan" malware on the target's device
Coper / Octo - A Conductor for Mobile Mayhem… With Eight Limbs?
https://www.team-cymru.com/post/coper-octo-a-conductor-for-mobile-mayhem-with-eight-limbs
Unlike email, there is a cost associated with sending each piece of physical mail, so this attack method must be delivering some level of success to the scammers behind it.
#CoSoSec