Home Malware Programs Adware 'HARASSMENT COMPLAINT' Email Scam

'HARASSMENT COMPLAINT' Email Scam

Posted: November 14, 2019

Cybercriminals and con artists often experiment with new social engineering tricks to get users to follow their instructions. Sometimes they rely on financial motivation by promising users that they can win great prizes by reviewing a file or email attachment, and, in other cases, they opt to go for fear-mongering strategies. In this description, we will talk about a tactic that involves the latter strategy.

The 'HARASSMENT COMPLAINT' email scam is a new email tactic that may be tailored according to the recipient's profile and field of work. According to the email, the victim has been accused of sexual harassment, and the message is an official complaint and warning from the 'U.S. EQUAL EMPLOYMENT OPPORTUNITY COMMISSION.' However, the message does not reveal any details about the case and, instead, it prompts the recipient to review the complaint by downloading an attached Microsoft Word document.

Beware of Phishing Emails Claiming to Come from the EEO

This is where it is important to mention that sexual harassment complaints are not handled via e-mail communication certainly, and the U.S. Equal Employment Opportunity Commission (EEO) would not send documentation this way. All incoming emails that claim to contain 'harassment complaints' are a lure used by con artists who are involved in malware propagation or phishing schemes.

If the victims end up downloading the attachment that accompanies the 'HARASSMENT COMPLAINT' Email Scam, they may see a fake document, which states that it has been protected via special measures, and the users must click 'Enable Content' or 'Enable Editing' to proceed – this is the last step of the tactic, and its goal is to allow the execution of the corrupted macro script that has been embedded in the document. Once this macro is initialized, it may use known vulnerabilities to download and initialize a harmful payload. So far, the 'HARASSMENT COMPLAINT' email scam has been observed to deliver copies of the TrickBot Trojan.

Email tactics have been around for ages, but they are still very efficient due to their ever-evolving nature. The con artists behind them adopt the latest trends in the phishing field and use a diverse set of social engineering tricks to receive escalated permissions and privileges from their victims.

Loading...