logo

The 25-Second Heist: Inside FAUX#ELEVATE’s “Inflated” Phishing Attack on French Corporations

ID: 030138f9-d966-5a2b-b746-18134bf22b9e

STIX ID: report--030138f9-d966-5a2b-b746-18134bf22b9e

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-03-31

Date Updated: 2026-04-23

Author: Ddos

...
...

Securonix researchers describe FAUX#ELEVATE, a sophisticated, targeted campaign using a malicious VBScript disguised as a resume to infect French-speaking corporate environments; the dropper uses extreme comment inflation to evade detection, performs a WMI domain-join check to target enterprise machines, employs a persistent UAC elevation loop, disables Defender, deploys ChromElevator to steal browser credentials and payment data, exfiltrates stolen profiles via smtp.mail.ru, and leaves a stealthy XMRig miner and backdoor on compromised hosts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.