Employers Beware: Microsoft Word ‘Resume’ Phish Delivers Quasar RAT
#1
Quote:A round of phishing emails purports to be from job seekers – but actually uses a slew of detection evasion tactics to download malware on victim systems.

Employers who receive an email from someone purporting to be a job applicant, with an attached resume, could fall victim to a difficult-to-detect phishing campaign peddling a remote-access tool used often for espionage.

Researchers with Cofense said they have recently spotted emails with malicious attachments delivering the Quasar open-source malware.  While the “job seeker” phishing theme may be fairly common, this particular campaign employs several sophisticated tactics that make it harder both for researchers to analyze — and company employees to detect.
 
“Organizations find a higher degree of difficulty with the ‘.doc’ file attachment distributing Quasar RAT itself, because the document employs a multitude of measures to deter detection,” Max Gannon, with Cofense, said in a Monday post. “Such methods include password protection—which is a built-in feature of Microsoft Word—and encoded macros.”

Read more here: https://threatpost.com/microsoft-word-re...re/147733/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
QOwnNotes
26.6.5 Added edit...Kool — 12:03
Microsoft Edge Moves to Two-Week Release...
Microsoft has anno...harlan4096 — 10:44
Bitdefender 27.0.60.337
Bitdefender 27.0.6...harlan4096 — 07:57
K-Lite Codec Pack 19.7.5 / 19.7.6 Update
Changes in 19.7.6 ...harlan4096 — 07:56
HWMonitor 1.64 for Windows
HWMonitor 1.64 for...harlan4096 — 07:55

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (39)Tedscolo
avatar (46)brakasig
avatar (45)JamesReshy
avatar (47)Francisemefe
avatar (40)leoniDup
avatar (39)Patrizaancem
avatar (39)biobdam
avatar (40)storoBox
avatar (48)kinotHeemn
avatar (39)Ceballos1976
avatar (40)efynu

[-]
Online Staff
There are no staff members currently online.

>