Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Malspam Email with Spoofed Fiber‑Optic Quote Delivers LausivLoader Malware

A malspam message impersonating a legitimate fiber‑optic quote request was quarantined by a mail gateway, preventing the LausivLoader loader from executing. The email failed SPF/DMARC checks, highlighting gaps in email authentication and phishing awareness that many organizations must address for audit readiness.

LiveThreat™ Intelligence · 📅 September 18, 2026· 📰 isc.sans.edu
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
isc.sans.edu

Malspam Email with Spoofed Fiber‑Optic Quote Delivers LausivLoader Malware

What Happened – A malspam message was caught by a customer’s mail gateway in late August. The email pretended to be a legitimate request for a price quotation on a fiber‑optic system, included a malicious attachment, and failed SPF and DMARC checks. The gateway quarantined the message, preventing the LausivLoader payload from reaching the end‑user.

Why It Matters for Trust & Control Assurance

  • Email authentication (SPF/DKIM/DMARC) is a core control that continuously proves the legitimacy of inbound mail and provides audit‑ready evidence of due‑diligence.
  • Phishing‑aware staff and automated sandboxing are essential to detect and contain malicious attachments before they can execute.
  • Continuous monitoring of mail‑gateway alerts supplies a defensible trail for auditors and regulators.

Who Is Affected – Organizations that rely on email for business communications, especially those using third‑party mail gateways or managed service providers.

Recommended Actions

  • Enforce strict SPF, DKIM, and DMARC policies and monitor alignment reports.
  • Deploy attachment sandboxing and malware‑analysis tools on inbound mail.
  • Conduct regular security‑awareness training focused on BEC and malspam indicators.
  • Review and document email‑security controls as part of your audit readiness package.

Technical Notes – The campaign used a standard business‑email‑compromise (BEC) lure, delivering the LausivLoader loader via a malicious Office document. No CVE or software flaw was exploited; the attack relied on social engineering and lack of proper email authentication.

Source: SANS Internet Storm Center – LausivLoader analysis

📰 Original Source
https://isc.sans.edu/diary/rss/33348 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →