الرئيس التنفيذي
أشرف الحادي

رئيس التحرير
فاطمة مهران

The domain of deception: Attackers deploy spyware under the guise of legal threats

Kaspersky has detected a rapidly escalating malicious campaign that has targeted over 1,100 corporate users since June 2025. The attackers pose as a legal firm and in their emails threaten recipients with lawsuits over alleged domain name patent violations, aiming to deploy malware. Victims who opened and launched the attached files – that mimicked legal documents – had a Trojan installed on their devices, and the attackers could spy on the content of their screens. Organizations across healthcare, finance, and education sectors have been targeted.
The campaign began with 95 emails on June 11 and has since continued to escalate. Apart from claiming that the recipient’s domain name violates patented combinations of a major brand and threatening litigation, in the email the fake legal bureau also expresses the patent holders’ interest in acquiring the domain and offers getting acquainted with the details of the alleged violations by opening the attached archive with “documents”. It is worth noting that the attackers, likely to avoid detection, attach an archive that is not password protected, and inside it includes another archive that is password protected and a file containing the password along with it.

An example of the malicious email
After the user entered the archive password and clicked on the alleged legal document inside, a Trojan was installed on the device. The user saw a message displayed that read, “This document cannot be opened on this device. Try opening it on another windows device,” and simultaneously the Tor Browser was covertly downloaded and installed in the background. Through it, the malware regularly sent snapshots of the user’s screen to the attackers over the Tor network. The malware also autostarts whenever the computer is restarted.
“This campaign is a sophisticated blend of psychological manipulation and technical deception, leveraging fear of legal action to coerce businesses into executing harmful files hidd en in attached archives. Its rapid growth since June 11 underscores the urgency for organizations to bolster defenses. Victims face the risk of losing their private data. Robust email security, employee training, and swift incident reporting are essential to counter this evolving threat,” comments Anna Lazaricheva, spam analyst at Kaspersky.
Kaspersky recommends corporate and individual users:
• Be careful when interacting with attachments. Do not open any attached archives (including those that are password-protected) that look suspicious. Do not run executable files, as they may deploy malware.
• Try to verify sender authenticity, confirm the legitimacy of any legal claims or entities mentioned in unsolicited emails.
• Implement endpoint protection to detect and block attack attempts.
• Educate staff on recognizing attack tactics.
• Immediately notify IT or cybersecurity teams if any files that have been attached to suspected phishing emails have been opened.

Related Posts:

OPPO Unveils Flagship Find X9 Pro and Comprehensive IoT Ecosystem at Cairo ICT 2025

Huawei at Cairo ICT 2025: Smart Solutions for Egypt’s Future

Central Bank of Egypt Participates in the 12th Edition of the Digital Payments, Financial Inclusion, and Digital Banking (PAFIX) International Conference and Exhibition

Raya Holding Reports Record-Breaking Results for Q3 and 9M 2025

Kaspersky reports 10% sales, highlights rising password stealers and spyware in the Middle East

Egypt Trust Launches a Series of Interactive Sessions and workshops at CAIRO ICT 2025

Heart of Hong Kong is Transformed into Winter Wonderland with Eight Iconic Buildings used as Canvas for New Immersive Lights Show

Reportage Properties expect Sales Exceeding SAR 500 Million by End of 2025

آخر الأخبار
رئيس الوزراء يستمع لعرض تقديمي حول مشروعات وزارة الاتصالات في مجال التحول الرقمي OPPO Unveils Flagship Find X9 Pro and Comprehensive IoT Ecosystem at Cairo ICT 2025 خطوات استخراج فيش جنائي مستعجل 2025 في 10 دقائق كيفية استخدام سجل عقارات الدولة الإلكتروني 2025 شركة eFinance تكشف «قفزة رقمية».. والرقابة المالية تطلق منصات جديدة في يناير Huawei at Cairo ICT 2025: Smart Solutions for Egypt’s Future "رئيس البريد يستعرض أمام رئيس الوزراء تطوير الخدمات وإطلاق الخدمات المالية الرقمية" وزيرة التضامن تزور المقر الرئيسي لبنك ناصر الاجتماعي .. وتتفقد سير العمل بداية قوية لـ Cairo ICT في دورته التاسعة والعشرين مصر تعيد رسم خريطة «سيادة البيانات» لحماية الخصوصية وتحفيز الابتكار "يوتن" تؤكد امتثالها القانوني والتزامها بالشفافية في إجراءات زيادة رأس المال الإمارات تتألق في أولمبياد الروبوتات وتحصل على المركز الأول بين 193 دولة انعقاد أول اجتماع بين جهاز الأموال المستردة وجمعية المطورين العقاريين لبحث آليات التعاون رسميًا.. محمد صلاح بالقائمة النهائية لجائزة أفضل لاعب فى أفريقيا استعلام تكافل وكرامة 2025 بالرقم القومي طريقة حجز عيادات التأمين الصحي أونلاين في مصر 2025 Oppo Find X9 Pro: المواصفات الكاملة والسعر المتوقع 2025 تقسيم مناطق الإيجار القديم في مصر: خريطة كاملة وتحديثات 2025 أسعار شقق ديارنا 2025: أحدث تحديثات الأسعار ومواصفات الوحدات البنك المركزي يشارك في المؤتمر والمعرض الدولي الثاني عشر للمدفوعات الرقمية والشمول المالي والبنوك ال...