the targets ’ computers and exfiltrateAttack.Databreachall kinds of documents , as well as log keystrokes and stealAttack.Databreachlogin credentials for sensitive accounts . According to court documents ( in Italian ) , the investigation began a few months after a security professional employed by ENAV , an Italian company responsible for the provision of air traffic services ( ATS ) and other air navigation services in Italy , flagged and reported a malicious attachment he received via email . The spear-phishing email was purportedly sentAttack.Phishingby an Italian attorney , but the infosec pro became suspicious and sent the attachment to security company Mentat Solutions for analysis . The attachment was found to contain the EyePyramid malware . After the authorities got involved , the investigation revealed that the email was , indeed , sentAttack.Phishingfrom the attorney ’ s email account , but that it was sentAttack.Phishingby someone who had compromised the account and accessed it via TOR .