Hackers Abuse DOCX, RTF, JS, and Python in Stealthy Boeing RFQ Malware Campaign
ID: 51bbceae-c111-54a0-98e2-5a4506443464
STIX ID: report--51bbceae-c111-54a0-98e2-5a4506443464
Feed Name: cybersecurityNews.com
A targeted phishing campaign labeled NKFZ5966PURCHASE used Boeing-themed DOCX lures that leverage hidden aFChunk-embedded RTF to execute hex-encoded JavaScript, spawn silent PowerShell which disables TLS/AMSI, download a Python 3.12 runtime from Filemail, and reflectively load an AES-256 encrypted DLL (Cobalt Strike) entirely in memory; multiple samples and at least one active payload URL were observed, with persistence via HKCU Run key RtkAudUService. Detection recommendations include monitoring DOCX aFChunk references, blocking Filemail URLs, and flagging the RtkAudUService Run key.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
