logo

XELERA Ransomware Campaign: Fake Food Corporation of India Job Offers Targeting Tech Aspirants

ID: 0824c43c-a108-5a56-b048-5f930705e827

STIX ID: report--0824c43c-a108-5a56-b048-5f930705e827

Feed Name: Seqrite Blog

Threat Score
75/100

Date Published: 2025-02-12

Date Updated: 2026-04-30

Author: Kartikkumar Jivani

...
...

Seqrite Labs analyzed a spear-phishing campaign using a malicious Word document (FCEI-job-notification.doc) that drops a PyInstaller-packed Python binary (jobnotification2025.exe). The binary unpacks a Discord-controlled bot that enables credential and file theft, remote-control and disruptive visual/audio attacks, and ultimately deploys XELERA ransomware which includes functions to kill explorer, change wallpapers, flood folders, and execute an MBR-corrupting MEMZ payload; the report includes file hashes, URLs, a Litecoin address, and MITRE ATT&CK mappings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.