Cybercriminals are ramping up a new phishing scheme aimed at U.S. residents, disguising malicious emails as official notices from the Social Security Administration (SSA).
These deceptive messages mimic government communication and claim a downloadable Social Security Statement is ready—luring recipients into opening a dangerous attachment.

Fake SSA Emails Deliver Dangerous Remote Access Malware in Stealthy Phishing Campaign
A new wave of phishing attacks is exploiting public trust in U.S. government agencies by mimicking official Social Security Administration (SSA) emails. These fake messages appear legitimate, using authentic-looking layouts and branding to deceive recipients into downloading malware.
Victims are urged to download what’s described as their Social Security Statement, but the attached files—camouflaged with misleading names like “ReceiptApril2025Pdfc.exe” and “SSAstatement11April.exe”—carry something far more sinister.
Inside these files is ScreenConnect, a legitimate remote administration tool repurposed by attackers to quietly hijack devices. Once installed, the tool gives full access to the system, enabling cybercriminals to run scripts, steal sensitive data, install malware, and move laterally across networks.
This attack is the work of a threat group identified by Malwarebytes as “Molatori,” named after the infrastructure domains they control, including atmolatori.icu and gomolatori.cyou. Their primary goal appears to be financial exploitation—intercepting banking credentials and personal identification information from compromised machines.
The operation is carefully engineered to bypass traditional defenses:
- Emails are sent from hijacked WordPress sites, giving the messages an air of legitimacy.
- Email content is embedded as images, sidestepping conventional text-based spam filters.
- The malware leverages trusted software, making detection more difficult for antivirus programs.
Malwarebytes flags these infections under RiskWare.ConnectWise.CST and actively blocks communications with known malicious domains.
What You Can Do:
- Always verify government-related messages through official SSA channels.
- Avoid opening unexpected attachments or clicking unfamiliar links.
- Keep your security software up to date, and consider advanced endpoint protection that can detect abuse of legitimate tools.
This campaign is a stark reminder that trust in familiar institutions is exactly what cybercriminals aim to exploit.




