RFQ Malware Campaign Uses DOCX, RTF, JS, and Python
ID: e122c26d-9d8b-555b-8720-d3793af348e2
STIX ID: report--e122c26d-9d8b-555b-8720-d3793af348e2
Feed Name: GBHackers
This report documents a stealthy spear‑phishing campaign (NKFZ5966PURCHASE) impersonating Boeing procurement that chains DOCX aFChunk‑embedded RTFs, OLE‑embedded JavaScript droppers, PowerShell downloaders, and a bundled Python 3.12 runtime to reflectively load a Cobalt Strike beacon in memory; operators reuse static AES/XOR keys and Filemail hosting while persisting via a Realtek‑like Run key launched through SyncAppvPublishingServer.vbs. Analysts recovered multiple artifacts (DOCX/RTF/JS/ZIP/Python/DLL) and live URLs, and recommend detections for embedded RTF hidden data, large RTFs, unusual Python runtimes in user profiles, and the specific Run key chain.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
