logo

Guloader Malware Being Disguised as Employee Performance Reports

ID: 087ce831-9b36-5e23-82ec-55842ad79b32

STIX ID: report--087ce831-9b36-5e23-82ec-55842ad79b32

Feed Name: ASEC

Threat Score
70/100

Date Published: 2026-01-08

Date Updated: 2026-04-26

Author: ATCP

...
...

AhnLab ASEC identified a phishing campaign delivering Guloader via a RAR attachment named "staff record pdf.exe" (disguised as a PDF). The loader downloads shellcode from a Google Drive URL and deploys Remcos RAT (C2: 196.251.116.219:2404,5000), providing remote access and data-theft capabilities (keylogging, screenshots, browser credential theft). The report includes the malware MD5 (c95f2a7556902302f352c97b7eed4159), the download URL, and guidance to exercise caution with email attachments and change passwords.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.