logo

Phishing Campaign Abuses Windows Search to Distribute Malware

ID: f6651d81-fa7c-5602-8ae3-ae196f587837

STIX ID: report--f6651d81-fa7c-5602-8ae3-ae196f587837

Feed Name: KnowBe4 Blog

Threat Score
60/100

Date Published: 2024-06-17

Date Updated: 2026-04-28

Author: Stu Sjouwerman

...
...

Trustwave researchers observed a phishing campaign delivering HTML attachments (often zipped and disguised as invoices) that abuse the Windows Search protocol to launch Explorer and present a shortcut (LNK) pointing to a remote batch (BAT) script; the attack relies on social engineering and user interaction to trigger subsequent malware installation, highlighting a deceptive technique that evades basic email scanners and exploits familiar OS behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.