Trojans spammed out in malicious wave of fake DHL emails

Graham Cluley
Graham Cluley
@
@[email protected]
@gcluley

DHLThere is a significant wave of malicious emails being spammed out presently, posing as notification messages from DHL.

If you make the mistake of opening the attached ZIP file you will be putting your computer at risk of infection by a Trojan horse.

There’s nothing new, of course, about cybercriminals disguising their attacks as notifications from DHL.

Sign up to our free newsletter.
Security news, advice, and tips.

This attack, though, is particularly aggressive and – as you can see in the examples below – uses a variety of different DHL-related subject lines, attachment names and message bodies:

Malicious DHL email

HELLO!

Dear Client, Recipient’s address is wrong

Print out the invoice copy attached and collect the package at our department

Best wishes , DHL Customer Services

Malicious DHL email

ATTENTION!
DEAR CLIENT , We were not able to deliver the postal package

Please print out the invoice copy attached and collect the package at our department

Pack it. Ship ip. No calculating, Your DHL .com Customer Services

Malicious DHL email

Good afternoon!

DEAR CUSTOMER, Recipient’s address is wrong
PLEASE PRINT OUT THE INVOICE COPY ATTACHED AND COLLECT THE PACKAGE AT OUR DEPARTMENT

Pack it. Ship ip. No calculating, Your DHL .com Customer Services

Malicious DHL email

Good afternoon!

Dear User , Delivery Confirmation: FAILED
Please print out the invoice copy attached and collect the package at our department
With respect to you, DHL Team

Here are just some of the different disguises we saw in a snapshot of less than one minute in a small selection of our spam traps:

Malicious DHL email subject lines

Sophos products intercept the attack, detecting the ZIP file as Troj/Invo-Zip and the Trojan horse contained within as Mac/EncPk-NS.

Dangerous emails claiming to come from courier companies are nothing new – it has become one of the most commonly-used methods by which hackers socially engineer unsuspecting users into opening a malicious attachment or clicking on a dangerous link.

Make sure that you and your friends are wise to the trick – and think before you click.


Graham Cluley is an award-winning keynote speaker who has given presentations around the world about cybersecurity, hackers, and online privacy. A veteran of the computer security industry since the early 1990s, he wrote the first ever version of Dr Solomon's Anti-Virus Toolkit for Windows, makes regular media appearances, and is the co-host of the popular "Smashing Security" podcast. Follow him on Twitter, Mastodon, Threads, Bluesky, or drop him an email.

What do you think? Leave a comment

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.