Cofense investigated a real ransomware delivery chain that starts with an email posing as a “Suggested Payment Plan” and a PDF attachment. The PDF contains a “Download” button that redirects victims to a malicious site to save an ISO file, ultimately leading to an encryptor download and system-wide file encryption with a ransom note and negotiation instructions.
Key findings
- Ransomware delivery began with an email pretexted as a “Suggested Payment Plan” and a PDF attachment.
- The PDF used a “Download” button to lure the user to a malicious download site and “Save a copy” of an ISO file.
- The ISO contained an EXE and an LNK shortcut pointing to the executable.
- Execution spawned a legitimate WinMerge.exe process as a loader and connected to attacker infrastructure to retrieve the encryptor (enc.exe).
- The encryptor scanned local drives, network shares, and databases, disabled security processes, and encrypted data, leaving files with a distinctive extension and dropping ransom notes.
Who’s being targeted
- Commonly targeted roles: Finance, Accounts Payable, Procurement, Executive leadership, All employees (email users).
- Affected industries: Multiple industries (large enterprises).
- Attack channels: email, website.
- Impersonated: Billing/collections sender using a generic Hotmail account, A file download page hosting a “proposal” file.
Awareness takeaways
- Treat unsolicited “payment plan/open balance” emails as high-risk, verify the sender using a trusted channel before opening attachments.
- Be suspicious of PDFs that push you to click a “Download” button, especially if it leads to an unfamiliar website.
- Never download or open ISO/EXE/LNK files to view a “document”, report it to security instead.
- Understand that ransomware operators try to make extortion sound like a normal business transaction; paying is not ‘routine’ and must be handled as an incident.
Red flags to watch for
- Sent from a generic Hotmail domain instead of a known vendor/company domain
- PDF contains a prominent “Download” button (unusual for legitimate invoices/payment plans)
- Redirects to an unrelated domain and asks the user to “Save a copy” of a file
- The “proposal” is delivered as an ISO disk image rather than a normal PDF/Word document
- Downloaded file includes shortcuts (LNK) and executables (EXE)
- Website/domain does not match the supposed sender
Read the video transcript
You get an email: subject line “Suggested Payment Plan” for an open balance, with a PDF attached. Looks routine, right? You open the PDF, there’s a big “Download” button. Click it, and you’re sent to driverupdate.sbs telling you to “Save a copy” of a proposal ISO file. That ISO hides an EXE and an LNK that kick off ransomware. Here’s the nasty part: opening that ISO runs the EXE via a shortcut, launches a legit-looking WinMerge.exe loader, pulls down enc.exe, and suddenly network drives, databases, everything, start getting encrypted with ransom notes dropped everywhere. If you see a “Suggested Payment Plan” email from a generic account and a PDF telling you to click Download or save an ISO, stop. Don’t open it, report it to Security immediately.