Do not open the file: Cyber Directorate warns against suspicious emails

The National Cyber Directorate warns against fake invoice emails containing links to malicious software. Attackers are using remote access tools while impersonating well-known companies like ESET.

Source
Do not open the file: Cyber Directorate warns against suspicious emails
Photo: Mako / מייל מתחזה לאיסט | צילום: פרטי

The National Cyber Directorate is warning against phishing emails disguised as invoices. These messages are allegedly sent via well-known invoice distribution services and contain a link to download a file. According to the directorate's analysis, the link directs users to download ScreenConnect—a remote access tool. While this is legitimate software, in this context, it is part of a malicious attack scheme that allows attackers to gain full control over the victim's computer.

One of the common versions of the email impersonates the information security company ESET. The email subject is "Tax invoice receipt number 70202," and it is presented as if it were sent from the official ESET antivirus store.

"Do not click on links, do not download files, and do not approve the installation of remote access software from emails you did not expect to receive," the Cyber Directorate emphasizes.

Experts recommend carefully verifying any invoice notifications, especially those received without clear context, and ensuring that operating systems and security software are kept up to date.

This is not the first time that impersonation of ESET has been recorded. In June 2025, similar emails were reported with subjects such as "Hello, below are the details of the antivirus license you purchased." In those instances, as in the current case, the goal was to trick users into installing malicious software under the guise of purchasing a license. The Cyber Directorate also strongly advises keeping up-to-date backups of important files.

Related News