Fake Payment Plan Email Drops Global Ransomware

Cofense · High sophistication
Last updated September 22, 2026

Cofense investigated a real ransomware delivery chain that starts with an email posing as a “Suggested Payment Plan” and a PDF attachment. The PDF contains a “Download” button that redirects victims to a malicious site to save an ISO file, ultimately leading to an encryptor download and system-wide file encryption with a ransom note and negotiation instructions.

Key findings

  • Ransomware delivery began with an email pretexted as a “Suggested Payment Plan” and a PDF attachment.
  • The PDF used a “Download” button to lure the user to a malicious download site and “Save a copy” of an ISO file.
  • The ISO contained an EXE and an LNK shortcut pointing to the executable.
  • Execution spawned a legitimate WinMerge.exe process as a loader and connected to attacker infrastructure to retrieve the encryptor (enc.exe).
  • The encryptor scanned local drives, network shares, and databases, disabled security processes, and encrypted data, leaving files with a distinctive extension and dropping ransom notes.

Who’s being targeted

  • Commonly targeted roles: Finance, Accounts Payable, Procurement, Executive leadership, All employees (email users).
  • Affected industries: Multiple industries (large enterprises).
  • Attack channels: email, website.
  • Impersonated: Billing/collections sender using a generic Hotmail account, A file download page hosting a “proposal” file.

Awareness takeaways

  • Treat unsolicited “payment plan/open balance” emails as high-risk, verify the sender using a trusted channel before opening attachments.
  • Be suspicious of PDFs that push you to click a “Download” button, especially if it leads to an unfamiliar website.
  • Never download or open ISO/EXE/LNK files to view a “document”, report it to security instead.
  • Understand that ransomware operators try to make extortion sound like a normal business transaction; paying is not ‘routine’ and must be handled as an incident.

Red flags to watch for

  • Sent from a generic Hotmail domain instead of a known vendor/company domain
  • PDF contains a prominent “Download” button (unusual for legitimate invoices/payment plans)
  • Redirects to an unrelated domain and asks the user to “Save a copy” of a file
  • The “proposal” is delivered as an ISO disk image rather than a normal PDF/Word document
  • Downloaded file includes shortcuts (LNK) and executables (EXE)
  • Website/domain does not match the supposed sender
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email: subject line “Suggested Payment Plan” for an open balance, with a PDF attached. Looks routine, right? You open the PDF, there’s a big “Download” button. Click it, and you’re sent to driverupdate.sbs telling you to “Save a copy” of a proposal ISO file. That ISO hides an EXE and an LNK that kick off ransomware. Here’s the nasty part: opening that ISO runs the EXE via a shortcut, launches a legit-looking WinMerge.exe loader, pulls down enc.exe, and suddenly network drives, databases, everything, start getting encrypted with ransom notes dropped everywhere. If you see a “Suggested Payment Plan” email from a generic account and a PDF telling you to click Download or save an ISO, stop. Don’t open it, report it to Security immediately.

Similar attacks

Phish Lures Steal Bank Logins via Telegram

Phish Lures Steal Bank Logins via Telegram

The report describes confirmed phishing activity targeting the financial sector, where victims were tricked into fake login pages via emails, links, or HTML attachments. The credentials entered were then exfiltrated to attackers through Telegram using APIs. The same report also highlights ongoing…

August 24, 2026
EvilTokens Uses Device Codes to Bypass MFA

EvilTokens Uses Device Codes to Bypass MFA

Microsoft reports that the EvilTokens phishing-as-a-service platform helped criminals compromise thousands of organizations by tricking users into completing a legitimate Microsoft “device code” login. The lure drives victims to enter a short code at microsoft.com/devicelogin, which unknowingly…

September 22, 2026
Malicious Calendar Invites Surge With Malware Links

Malicious Calendar Invites Surge With Malware Links

Attackers are sending fake calendar meeting invites that can be automatically added to a victim’s calendar, even if the email is blocked. A documented example used a Google Calendar invite with a financial “invoice credit” lure to drive victims to a hosted webpage and download a malicious…

September 18, 2026
Fake AI Trading Bot Steals Crypto Wallet Passwords

Fake AI Trading Bot Steals Crypto Wallet Passwords

Researchers observed real campaigns where a fake “AI crypto trading agent” website tricked victims into downloading malware that silently replaces browser wallet extensions and steals the wallet password when it’s typed. The same reporting also describes invoice emails using QR codes to push…

September 17, 2026
M365 “Direct Send” Abused for Internal-Looking Phish

M365 “Direct Send” Abused for Internal-Looking Phish

Researchers observed a real phishing campaign that abused Microsoft 365’s Direct Send feature to make emails look like they came from the victim organization’s own domain, without compromising an employee account. The campaign was timed to mimic human sending patterns during U.S. Eastern business…

September 14, 2026
M365 Direct Send Spoofs Internal HR & Finance

M365 Direct Send Spoofs Internal HR & Finance

Researchers observed a real phishing campaign that abused Microsoft 365’s “Direct Send” feature to deliver messages that looked like they came from trusted internal addresses (HR, accounting, admin). The emails commonly used familiar business lures like invoices, payment approvals, voicemail…

September 11, 2026