logo

New “Paste and Run” Phishing Technique Makes CTRL-V A Cyber Attack Accomplice

ID: 738a01a0-5a39-5815-b7fa-f9e3ebbf1c6b

STIX ID: report--738a01a0-5a39-5815-b7fa-f9e3ebbf1c6b

Feed Name: KnowBe4 Blog

Threat Score
60/100

Date Published: 2024-07-05

Date Updated: 2026-04-28

Author: Stu Sjouwerman

...
...

Ahnlab researchers uncovered a phishing campaign that presents a fake Word Online page instructing victims to paste a clipboard PowerShell command into the Windows Run dialog; the command connects to a web host, downloads an HTA, and installs DarkGate malware. The attack leverages a novel "paste-and-run" social engineering technique to bypass normal attachment-detection and relies on user interaction, so defenders should emphasize user awareness and monitor for related PowerShell and HTA activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.