LockBit Ransomware Distributed via Word Files Disguised as Resumes
ID: 3394a27c-88da-5f01-81cb-28799e32c091
STIX ID: report--3394a27c-88da-5f01-81cb-28799e32c091
Feed Name: ASEC
AhnLab ASEC reports that LockBit 3.0 ransomware is being distributed through malicious Word documents (often disguised as resumes) that reference external DOTM templates in settings.xml.rels; these templates contain obfuscated VBA macros which run PowerShell to download and execute LockBit executables. The report includes example malicious document names, identified external DOTM and EXE URLs, MD5 hashes for DOTM/DOCX/EXE artifacts, and screenshots of infection and ransom notes, and warns that various malware families are using the same resume-themed lure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
