Italy's government computer emergency response team publishes a tally every week of what hit the country. The edition covering September 5 to 11 counts 170 malicious campaigns, 136 of them aimed specifically at Italian targets, and 1,391 indicators handed to the public bodies CERT-AGID supports. One item in the list deserves separating from the count, because it is aimed at companies rather than consumers.
CERT-AGID found a phishing site impersonating the Registro delle Imprese, the national business register every Italian company appears in. The fraudulent page collects the company name, the codice fiscale and the IBAN. That is the exact set needed to redirect an invoice payment or to open something in the firm's name, and registry correspondence is the kind of mail a finance office is trained to action rather than question.
Refunds are still the lure that works
The bulk of the week was the familiar Italian pattern. Refunds drove 65 phishing campaigns abusing the Agenzia delle Entrate, PagoPA and INPS, one strand of which promised an income tax rebate and collected tax codes and full card details in exchange. Unpaid fines drove another 25, delivered by email and SMS dressed in SEND and PagoPA branding, the same theme we wrote about when it dominated a week in August. Banking lures took 16, naming Findomestic, ING, Inbank, Intesa Sanpaolo, Klarna, Mediolanum, N26, PayPal and Saxo Trader. Across the week, 36 brands were abused over 20 separate themes.
One other campaign stands out. A page borrowing the graphics and logos of the Fascicolo Sanitario Elettronico, Italy's electronic health record portal, staged a fake account verification in order to harvest personal data. The health service has been a recurring costume, including a fake pharmacy refund page that took card details last month.
Eleven families, and three of them want your phone
CERT-AGID logged 11 malware families over the seven days. FormBook led with five campaigns on payment, banking, order and legal themes, arriving inside TAR, ZIP and RAR archives. Remcos ran four, MassLogger three, SnakeKeylogger and XWorm two each, and AgentTesla, Grandoreiro and NeptuneRat one apiece. Compressed archives and Office-style attachments remain the delivery method of choice.
The Android side is the part worth noting. BingoMod, Gigabud and MantaxOtax all arrived as malicious APK files advertised over SMS links on banking themes, which puts three separate mobile banking trojans into a single week of Italian traffic. An SMS carrying a download link rather than a link to a bank's own site is the tell.
What a finance office should refuse
No Italian public body asks for an IBAN, a codice fiscale or card details through a link in an email or a text message, and neither the business register nor the tax agency issues refunds that way. A registry, fine or refund notice is a reason to open the official portal directly rather than to click anything in the message. On Android, a text asking you to install an application from outside the Play Store is the attack, whatever brand it is wearing.
The weekly summary is written by Francesco Tozzi and published by CERT-AGID with the full indicator set attached; the original bulletin is here, and our Italy country profile tracks the longer trend.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.