Movistar phishing scam targets users with trojan malware
A sophisticated phishing campaign impersonating Spanish telecommunications giant Movistar is currently underway, delivering malicious Trojans to unsuspecting users' devices. Cybersecurity firm ESET has flagged the scheme, highlighting a surge in fake invoices designed to lure individuals into downloading harmful software – a tactic that, despite its age, continues to prove remarkably effective.

The deceptive invoice trick
The attackers' method is deceptively simple: they send emails mimicking official Movistar communications, presenting a fabricated invoice that demands immediate payment. While these scams have been circulating for years, the sheer persistence of cybercriminals in resurrecting them speaks volumes about the vulnerability of many users. This latest iteration specifically targets Movistar customers, capitalizing on the brand’s strong reputation and widespread recognition.
The phishing emails appear convincingly genuine at first glance, utilizing Movistar’s branding and language. However, closer inspection reveals inconsistencies in the sender's domain – a telltale sign of malicious intent. The true danger lies in the “Download Invoice” button, which redirects users to a cleverly disguised website.
What makes this campaign particularly insidious is the verification process implemented before the download. Rather than directly initiating the malware download, the attackers present a challenge, ostensibly to prevent automated bots. This allows the malicious website to remain active for longer, increasing its chances of infecting vulnerable devices. Once a user completes the verification, a compressed file containing the fake Movistar invoice is downloaded—but instead of a bill, it contains a dangerous HTA file.
This HTA file, rarely used for legitimate invoices, acts as a redirector, leading to a server controlled by the cybercriminals. The payload? A Trojan, designed to stealthily harvest sensitive data from the infected device. This includes login credentials, browsing history, and other personal information, which can then be exploited for further attacks or identity theft.
ESET's findings underscore a persistent threat: cybercriminals continue to leverage familiar brands to deceive users and compromise their digital security. The ease with which these scams succeed highlights the need for enhanced user awareness and vigilance when dealing with unsolicited emails, particularly those requesting downloads or personal information.
The proliferation of these attacks demonstrates that even well-established security measures are not foolproof. A critical element is individual responsibility: users must exercise caution and skepticism when encountering suspicious emails, regardless of the sender’s apparent legitimacy. The digital landscape demands a proactive approach to cybersecurity, prioritizing awareness and critical thinking over blind trust.
