Beware of Weaponized Employee Performance Reports that Deploys Guloader Malware
ID: 76ee6dbd-0ec3-5e78-a605-0d67fca81b3b
STIX ID: report--76ee6dbd-0ec3-5e78-a605-0d67fca81b3b
Feed Name: cybersecurityNews.com
Threat Score
A phishing campaign distributes Guloader disguised as an employee performance report (NSIS executable inside a RAR named “staff record pdf.exe”) which downloads encrypted shellcode from Google Drive and injects it into memory to deploy Remcos RAT; C2 infrastructure is identified at 196.251.116.219 on ports 2404 and 5000, enabling persistent remote access and data theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
