[Exec] Malware attack

exec at hamiltonrasc.ca exec at hamiltonrasc.ca
Thu Apr 2 15:52:38 EDT 2026


All

I felt the draft was very good and also we were offering a little too much information in some sections. I've redrafted it below and added information from the Canadian Centre for Cyber Security. Assuming National does not have a template,



Dear Members,

We are writing to inform you of a recent security incident involving the RASC Hamilton website. Earlier this month, our website was compromised by a malicious attack.  A detailed technical analysis confirmed that this was a multi-stage malware infection to use our website for their spamming activities.

We have taken immediate steps to secure the website and prevent further issues:

  *   Upon detection, the site was immediately taken offline, and we completed a full recovery within 24 hours using a clean backup from January 2026.
  *   Fully restored the site from a clean backup
  *   Removed all malicious files and access points
  *   Installed enhanced security monitoring tools
  *   Enabled Two-Factor Authentication (2FA) for administrators
  *   Disabled outdated plugins and potential attack vectors
  *   Strengthened hosting and administrative account security

The website is now fully restored and secured, and we are continuing to monitor for any unusual activity. At this time, there is no evidence of ongoing compromise.

While it appears they were not interested in any RASC information based on our investigation, the following member information may have been accessed:

  *   Names
  *   Email addresses

As a precaution, we recommend that members:

  *   Change your password on the RASC Hamilton website
  *   If you used the same password on other websites, please change it there as well.
  *   Remain cautious of any unexpected or suspicious emails including those from other RASC members.
  *   Review the information provided below from the Canadian Centre for Cyber Security.



We take the security of our members' information very seriously and regret any concern this may cause. If you have any questions or concerns, please feel free to reach out.

Thank you for your understanding and continued support.

Canadian Centre for Cyber Security.
How to identify a phishing attack
Phishing attacks can be delivered in many ways, but they all play on trust, urgency and other aspects of human psychology. Fear, excitement, authority, curiosity and trust could all be reactions to a phishing message. Phishing attacks typically follow a similar sequence. Knowing how to identify these steps can help protect your organization against phishing.

Step 1: The bait
As described above, there are many ways that the threat actor can set the bait. They may craft a message that appears to come from a well-known bank or service provider. They use spoofing techniques and send the message to numerous recipients in the hope that some will take the bait.

In spear phishing and whaling attacks, the threat actor first gathers details about the target. For example, they harvest information from social media profiles, company websites and Internet activity to create a customized message.

In vishing attacks, the threat actor might use a computerized auto-dialer (known as a robocall) or an AI-generated voice of a known person to deliver the fraudulent message to many victims.

Step 2: The hook
The hook occurs when the victim believes the message is from a trusted source and the message contains information that entices the victim to take immediate action. For example, the message may ask the user to resolve an urgent issue with their account.

If the victim clicks the link in the message, they will unknowingly be redirected to the threat actor's fake version of the real website. The victim provides sensitive information, such as login credentials, which is sent to the threat actor. If the victim opens an infected attachment, their device may become infected if the malicious code executes.

Step 3: The attack
Threat actors can use stolen user credentials to access the victim's accounts. They may use an infiltrated email account to send more phishing emails to the victim's contacts. If the victim has privileged access (for example, to an organization or company account, system or network), the threat actor could gain access to sensitive corporate data and critical systems.

Phishing characteristics
Although AI is making it hard to detect certain phishing characteristics, such as poor spelling or a robotic tone, there are other signs to be aware of.
Something may be phishy if:

  *   the sender makes an urgent request with a deadline
  *   the sender requests your personal or confidential information
  *   the sender asks you to log in via a provided link
  *   the offer sounds too good to be true
  *   the communication is unsolicited and includes:
     *   attachments
     *   links to websites or web forms (these may be spoofed)
     *   QR codes
     *   login pages
     *   a claim to be government or bank officials
  *   you don't recognize the sender
     *   remember, addresses can be spoofed
     *   a known sender isn't necessarily a trusted sender

You can reduce your risk of falling victim to a phishing attack by:

  *   remaining calm; phishing depends on creating a sense of urgency
  *   avoiding sending sensitive information by email or text
  *   reducing the amount of personal information they post online
  *   enabling a spam blocker in their mobile device application settings
  *   avoiding using any form of simplified contact response, such as clicking on hyperlinks, loading QR codes or replying to suspicious texts
  *   filtering spam emails (unsolicited junk emails sent in bulk)
  *   verifying the sender's legitimacy by contacting the sender through a separate channel, for example:
     *   if they receive a call from their bank, hanging up and visiting or calling their local branch
     *   if they receive an email from their Internet service provider, contacting the service provider through their web form
     *   if they receive a text from a company or provider on their phone, responding by email from their computer
  *   avoiding SMS over the air, flash call (a near-instant dropped call that is automatically placed to a mobile number) and SMS as an MFA method


Sincerely,
Shail Choksi
Webmaster
RASC Hamilton

Regards
Chuck Bennett P. Eng.
C: 905.630.5178
[Linkedin-icon]<https://ca.linkedin.com/in/mrcharlesbennett>  [Twitter-icon] <https://twitter.com/Chuck_Bennett_>

This email, including any attachments, may contain confidential and privileged information and material, including confidential and privileged communications and/or proprietary work product provided for the sole use of the intended recipient, and shall not be used, disclosed or reproduced without the express written consent.  If you are not the intended recipient or an employee or agent responsible for delivering this message to a named recipient, please notify us immediately, and permanently destroy this message and any copies you may have. Thank you.

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://hamiltonrasc.ca/pipermail/exec_hamiltonrasc.ca/attachments/20260402/4d4949d0/attachment-0001.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image001.gif
Type: image/gif
Size: 1295 bytes
Desc: image001.gif
URL: <http://hamiltonrasc.ca/pipermail/exec_hamiltonrasc.ca/attachments/20260402/4d4949d0/attachment-0002.gif>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image002.gif
Type: image/gif
Size: 1351 bytes
Desc: image002.gif
URL: <http://hamiltonrasc.ca/pipermail/exec_hamiltonrasc.ca/attachments/20260402/4d4949d0/attachment-0003.gif>


More information about the Exec mailing list