logo

Hackers Abuse DOCX, RTF, JS, and Python in Stealthy Boeing RFQ Malware Campaign

ID: 51bbceae-c111-54a0-98e2-5a4506443464

STIX ID: report--51bbceae-c111-54a0-98e2-5a4506443464

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-04-02

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A targeted phishing campaign labeled NKFZ5966PURCHASE used Boeing-themed DOCX lures that leverage hidden aFChunk-embedded RTF to execute hex-encoded JavaScript, spawn silent PowerShell which disables TLS/AMSI, download a Python 3.12 runtime from Filemail, and reflectively load an AES-256 encrypted DLL (Cobalt Strike) entirely in memory; multiple samples and at least one active payload URL were observed, with persistence via HKCU Run key RtkAudUService. Detection recommendations include monitoring DOCX aFChunk references, blocking Filemail URLs, and flagging the RtkAudUService Run key.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.