Intuit invoices from Sequoia used for malware
Summary
This blueAPACHE post reports: Another phishing attack, but with a local financial entity and a real Inuit email address. As we have mentioned in previous blog entries, it is often easy to identify the less mature malware attacks by simply checking the email addresses or holding you mouse over any links to show their true destination. It concerns emPOWER Security, Human Risk Management. Published in 2016. Figures, product names and event details reflect that time; for current information see the linked service pages.
Key facts
| Label | Value |
|---|---|
| Publication year | 2016 |
| Services referenced | emPOWER Security, Human Risk Management |
| Topic | Intuit invoices from Sequoia used for malware |
Article
Another phishing attack, but with a local financial entity and a real Inuit email address.
As we have mentioned in previous blog entries, it is often easy to identify the less mature malware attacks by simply checking the email addresses or holding you mouse over any links to show their true destination.
Today, we received notification of emails that present as invoices from Sequoia Financial Group; a legitimate financial services company in Melbourne and Sydney.
The email appears genuine, seemingly sent from the popular Intuit Quickbooks accounting software. The sender address is quickbooks@notification.intuit.com, appearing exactly as would expect for an online invoice notification. None of the normal fake email tell tale signs were present – this looked for all intents and purposes to be correct. Except it isn’t.
The problem is the view invoice link. The link is difficult to read when hovering your mouse over, as it is automatically generated through a popular mail management program. Clicking to access the invoice will automatically download a file entitled Invoice_70861.zip. The file inside the downloaded zip file is Invoice_70861.js.
If you open this file to read the invoice, the trojan is installed and no file is displayed.
The trojan then accesses the Kernel Security Device Driver (KsecDD) of Windows, reads personal information, creates writeable files in a temporary directory, writes PE32 executable console files to disk, creates mutants, reads Windows trust settings and system certificate settings, connects to LPC ports, enters URL in binary, connects to two domains (USA and UK based IP address), and contacts 6 hosts located in Germany, Russia and United Kingdom. At this point, you may well have lost control of your computer.
John Collignon, Sequoia Financial Group’s Head of Superannuation, stated that the company “is aware of the emails and that someone is pretending to be us”. He confirmed that Sequoia had received reports today of emails masquerading as Xero and Quickbooks invoices, and explained he was not aware why the company brand was being maliciously used by hackers to distribute malware.
Sequoia are not the only company being targeted in the bulk email campaigns trying to distribute Invoice_70861.js. Our security systems are blocking thousands of these emails each day. Not all share the levels of detail as seen in the Sequoia email, which makes it stand out.
Any company can be targeted by hackers looking to benefit from your reputable brand to encourage individuals to unwittingly install trojans or malware. This attack using Sequoia’s brand reinforces:
- Australian businesses are not immune to being targeted. We need mature levels of awareness, process and security to manage the risk.
- Security is becoming the key focus for IT departments around the world,. Failure to secure your data can have far reaching ramifications.
- Quality training to educate staff, customers and suppliers on how to spot phishing emails and social engineering attacks should be high on your education priorities.
- If you receive an email you are unsure of, phone the company directly to validate it before clicking any links.
**Note
** blueAPACHE explicitly agrees that Sequoia Financial Group is in no way responsible for the distribution of Invoice_70861.js. We suspect their brand was likely hijacked by an unknown party to invoke higher levels of confidence in the email, in hope that more recipients would access the invoice and unknowingly install the trojan software.
For more information on how to better secure your business, contact the blueAPACHE account team.
Related
Frequently asked questions
What phishing attack does this post describe, and which brand did it impersonate?
The post describes a phishing attack impersonating Sequoia Financial Group, sent from an address appearing to be quickbooks@notification.intuit.com, presenting as an Intuit QuickBooks invoice notification.
What happens if a recipient opens the attached file, per the post?
Opening the downloaded Invoice_70861.js file (inside Invoice_70861.zip) installs a trojan with no file displayed, which the post describes as accessing the Windows Kernel Security Device Driver, reading personal information, and creating files, without further prompt.
Where does the post say the trojan connects to once installed?
The post states the trojan connects to two domains based in the USA and UK, and contacts six hosts located in Germany, Russia and the United Kingdom.
What did Sequoia's John Collignon say about the impersonation?
John Collignon, Sequoia Financial Group's Head of Superannuation, said the company was aware of the emails and that someone was pretending to be Sequoia, confirming reports of both Xero- and QuickBooks-branded fake invoices.
Is this post still current?
No. It describes a specific 2016 phishing campaign and malware sample. For blueAPACHE's current security services, see the emPOWER Security page linked below.
Source
https://www.blueapache.com/blog/intuit-invoices-from-sequoia-used-in-malware-attack/
Knowledge Base
What is the blueAPACHE blog post 'Intuit invoices from Sequoia used for malware' about?
It describes a phishing attack in which emails posing as invoices from Sequoia Financial Group, a legitimate financial services company in Melbourne and Sydney, were sent using a spoofed Intuit QuickBooks notification address to trick recipients into installing a trojan.
What email address did the phishing emails appear to come from?
The emails appeared to come from quickbooks@notification.intuit.com, mimicking a genuine Intuit QuickBooks online invoice notification.
What happens when a recipient clicks the 'view invoice' link in the phishing email?
Clicking the link automatically downloads a file called Invoice_70861.zip, which contains a file named Invoice_70861.js; opening this file installs a trojan without displaying any invoice.
What does the trojan do once installed on a victim's computer?
According to blueAPACHE, the trojan accesses the Kernel Security Device Driver (KsecDD) of Windows, reads personal information, creates writeable files in a temporary directory, writes PE32 executable console files to disk, creates mutants, reads Windows trust and system certificate settings, connects to LPC ports, enters URLs in binary, connects to two domains (US and UK based IP addresses), and contacts six hosts located in Germany, Russia, and the United Kingdom.
Did Sequoia Financial Group send these malicious emails?
No. blueAPACHE explicitly states that Sequoia Financial Group is in no way responsible for distributing Invoice_70861.js; the company's brand was likely hijacked by an unknown party to make the phishing email appear more credible.
What did Sequoia Financial Group say about the fraudulent emails?
John Collignon, Sequoia Financial Group's Head of Superannuation, said the company was aware of the emails and that someone was pretending to be them, and confirmed Sequoia had received reports of emails masquerading as both Xero and QuickBooks invoices, though he was unsure why the brand was being used by hackers.
Was Sequoia the only company targeted in this malware campaign?
No, Sequoia was not the only company targeted. blueAPACHE's security systems were blocking thousands of similar emails each day, though not all had the same level of detail as the Sequoia-branded email.
What recommendations does blueAPACHE give to protect against this type of attack?
blueAPACHE recommends developing mature awareness, processes and security to manage risk; making security a key IT department focus; providing quality training to staff, customers and suppliers on spotting phishing and social engineering attacks; and phoning a company directly to validate any suspicious email before clicking links.
When was this blueAPACHE blog post about the Sequoia/Intuit malware attack published?
The post was published on September 13, 2016, according to the page's listed publication date.
Images on This Page
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a6ffec7d87be5a881637bba_31b5a84971e1d1ce71dc99ca059bfbde_blueAPACHE.svg
blueAPACHE logo on a dark blue background
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bef56ba2a604e908fd4_invoice-malware.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a713402a5a7f7ebf553f0bf_Background-Top.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bf156ba2a604e90908c_Sequoia.jpeg
Sequoia
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bf156ba2a604e90909d_Thousands-of-emails.jpeg
Thousands of emails
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701b59b153d68a8eeb0e36_BBanner-1-Windows-10-is-out.-AI-is-in.-.avif
You’ve Invest in Security. So Why Are Breaches Still Happening?
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb807b7741bf53e298a_BBanner-1-Windows-10-is-out.-AI-is-in.-8.avif
EOFY 2026: The Reset Is Done – Now It’s About Getting Ahead
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d0_BBanner-2-When-support-ends-risk-begins-4.avif
Why Every Business Needs AI Guardrails
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d7_BBanner-2-When-support-ends-risk-begins-3.avif
Ransomware Incident Response: Why Paying the Ransom Is a Failure of Preparation
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb707b7741bf53e297d_BBanner-2-When-support-ends-risk-begins-1.avif
The 7 Cyber Truths Boards Must Act On In 2026
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29f9_BBanner-1-Windows-10-is-out.-AI-is-in.-7.avif
Reflecting on an Outstanding 2025 – Thank You for Your Partnership
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e2a0c_Procurement-Portal.avif
The blueAPACHE e-Store: IT purchasing made simple
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29ec_BBanner-1-Windows-10-is-out.-AI-is-in.-5.avif
Building Our Cyber Safe Culture: A Practical Guide for CSAM 2025
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fbfad31fa678fefd51a_6a704f395a0a01b8e482853a_support-monitor.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4563e_6a704f3a400fc8e661400519_support-user.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45639_6a704f3a91ffd7d0dbc40847_support-phone.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4562f_6a704f3747d60bd3f65b7a31_support-globe.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45636_6a704f38eb60992797acf5d9_support-mail.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45633_6a704f3a07b7741bf54f2122_support-speech-bubble.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a707520ca872d1b5a69a518_Sensiba.avif
Sensiba ISO/IEC 27001 Certified badge with a diamond-shaped logo below the text.