Using MailChimp makes malware campaigns a little bit more successful

Thanks to anti-spam infrastructure that we have collectively built over the years nowadays are very hard to send thousands or millions of emails. Sending one email is easy, sending millions is not, because of this companies tend to move their mail delivery operations to email service providers or ESPs. ESPs can handle unsubscribe requests, bounces, and deal with the listing of the mail servers on DNS blacklists.

ESPs don’t tolerate spammers, so they are not along their usual customers. But for every rule there is an exception, our cybersecurity team found that cybercriminals have gained access to Mailchimp’s systems. For now, it is unclear how they managed to do this; possibilities range from a vulnerable third-party plug-in that integrates into MailChimp to a malware that is present in MailChimp itself, or by using stolen customer credentials.
Because email security products scan attachments, but they are avoiding inspecting links beyond the URL cybercriminals used in their last campaign emails claiming to link either to an invoice or fax. This kind of technique is helping cybercriminals to make emails harder to block.
