Geeks for your information
Employers Beware: Microsoft Word ‘Resume’ Phish Delivers Quasar RAT - Printable Version

+- Geeks for your information (https://www.geeks.fyi)
+-- Forum: News (https://www.geeks.fyi/forumdisplay.php?fid=105)
+--- Forum: Privacy & Security News (https://www.geeks.fyi/forumdisplay.php?fid=107)
+--- Thread: Employers Beware: Microsoft Word ‘Resume’ Phish Delivers Quasar RAT (/showthread.php?tid=8127)



Employers Beware: Microsoft Word ‘Resume’ Phish Delivers Quasar RAT - silversurfer - 27 August 19

Quote:A round of phishing emails purports to be from job seekers – but actually uses a slew of detection evasion tactics to download malware on victim systems.

Employers who receive an email from someone purporting to be a job applicant, with an attached resume, could fall victim to a difficult-to-detect phishing campaign peddling a remote-access tool used often for espionage.

Researchers with Cofense said they have recently spotted emails with malicious attachments delivering the Quasar open-source malware.  While the “job seeker” phishing theme may be fairly common, this particular campaign employs several sophisticated tactics that make it harder both for researchers to analyze — and company employees to detect.
 
“Organizations find a higher degree of difficulty with the ‘.doc’ file attachment distributing Quasar RAT itself, because the document employs a multitude of measures to deter detection,” Max Gannon, with Cofense, said in a Monday post. “Such methods include password protection—which is a built-in feature of Microsoft Word—and encoded macros.”

Read more here: https://threatpost.com/microsoft-word-resume-phish-malware/147733/