logo

RFQ Malware Campaign Uses DOCX, RTF, JS, and Python

ID: e122c26d-9d8b-555b-8720-d3793af348e2

STIX ID: report--e122c26d-9d8b-555b-8720-d3793af348e2

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-04-02

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

This report documents a stealthy spear‑phishing campaign (NKFZ5966PURCHASE) impersonating Boeing procurement that chains DOCX aFChunk‑embedded RTFs, OLE‑embedded JavaScript droppers, PowerShell downloaders, and a bundled Python 3.12 runtime to reflectively load a Cobalt Strike beacon in memory; operators reuse static AES/XOR keys and Filemail hosting while persisting via a Realtek‑like Run key launched through SyncAppvPublishingServer.vbs. Analysts recovered multiple artifacts (DOCX/RTF/JS/ZIP/Python/DLL) and live URLs, and recommend detections for embedded RTF hidden data, large RTFs, unusual Python runtimes in user profiles, and the specific Run key chain.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.