XELERA Ransomware Campaign: Fake Food Corporation of India Job Offers Targeting Tech Aspirants
ID: 0824c43c-a108-5a56-b048-5f930705e827
STIX ID: report--0824c43c-a108-5a56-b048-5f930705e827
Feed Name: Seqrite Blog
Seqrite Labs analyzed a spear-phishing campaign using a malicious Word document (FCEI-job-notification.doc) that drops a PyInstaller-packed Python binary (jobnotification2025.exe). The binary unpacks a Discord-controlled bot that enables credential and file theft, remote-control and disruptive visual/audio attacks, and ultimately deploys XELERA ransomware which includes functions to kill explorer, change wallpapers, flood folders, and execute an MBR-corrupting MEMZ payload; the report includes file hashes, URLs, a Litecoin address, and MITRE ATT&CK mappings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
