New “Paste and Run” Phishing Technique Makes CTRL-V A Cyber Attack Accomplice
ID: 738a01a0-5a39-5815-b7fa-f9e3ebbf1c6b
STIX ID: report--738a01a0-5a39-5815-b7fa-f9e3ebbf1c6b
Feed Name: KnowBe4 Blog
Ahnlab researchers uncovered a phishing campaign that presents a fake Word Online page instructing victims to paste a clipboard PowerShell command into the Windows Run dialog; the command connects to a web host, downloads an HTA, and installs DarkGate malware. The attack leverages a novel "paste-and-run" social engineering technique to bypass normal attachment-detection and relies on user interaction, so defenders should emphasize user awareness and monitor for related PowerShell and HTA activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
