Google Forms Weaponized: New “PureHVNC” Campaign Targets Professionals via LinkedIn
ID: e6f34aec-48fa-5edb-a23d-81f2c9b19490
STIX ID: report--e6f34aec-48fa-5edb-a23d-81f2c9b19490
Feed Name: securityonline.info
Malwarebytes Labs uncovered a targeted campaign that lures professionals via LinkedIn and branded Google Forms to download ZIP archives (hosted on Dropbox or via Google redirects) containing a malicious executable and hidden DLL which deploys the PureHVNC RAT; the malware provides remote execution, data theft from browsers/crypto wallets and apps (Telegram, Foxmail), persistence via scheduled PowerShell tasks, and uses DLL hijacking, WMI checks, and sandbox/debugger detection for evasion—users should not run executables to view documents and must verify sources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
