Unknown cyber actors targeted a US renewable energy company in a spear-phishing campaign that impersonated a US-based financial institution and promised access to more than $62 million in funding. The phishing email used a fraudulent loan theme, spoofed financial and government-linked entities through registered domains, email subjects, and attached PDFs, and directed the recipient to download a fake Windows banking application from secureportal[.]online. Supporting lures included a document spoofing the UK National Crime Agency and another appearing to contain SWIFT information, indicating an effort to build credibility across multiple institutions.
The FBI, in coordination with DHS-CISA, said the malicious executable contacted secureportal[.]online and warned that the activity matched a broader campaign active since at least 2017. Additional reporting linked the infrastructure to numerous lookalike domains, fake login portals, and backdoored installers masquerading as banks in multiple regions; the installers were reportedly built with the open-source Squirrel framework and likely delivered TeamViewer-derived remote access trojans with low antivirus detection. Authorities recommended updated anti-malware, application control, reduced administrator privileges, and careful verification of unsolicited emails, attachments, and web addresses.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
On 27 May 2021, Cyjax published analysis expanding on the FBI indicators and tied the incident to a wider infrastructure cluster using fake banking portals and backdoored installers. Cyjax said the malware appeared to use Squirrel-built applications and likely TeamViewer-derived remote access capability.
On 12 May 2021, the FBI issued Private Industry Notification 20210512-001, coordinated with DHS-CISA, describing the spear-phishing campaign and associated indicators. The notice warned that the attackers used spoofed financial branding, fraudulent PDFs, and a malicious executable that contacted secureportal(.)online.
In February 2021, unknown cyber actors spear-phished a renewable energy company while impersonating a US-based financial institution. The email promised more than $62 million in funding and directed the recipient to download a fake Windows application from attacker-controlled infrastructure.
Cyjax assessed the broader spear-phishing and fake banking application campaign had been active since at least 2017, using lookalike domains and fake portals to impersonate financial institutions across multiple regions.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 34 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.