Phishing Campaign Abuses Windows Search to Distribute Malware
ID: f6651d81-fa7c-5602-8ae3-ae196f587837
STIX ID: report--f6651d81-fa7c-5602-8ae3-ae196f587837
Feed Name: KnowBe4 Blog
Threat Score
Trustwave researchers observed a phishing campaign delivering HTML attachments (often zipped and disguised as invoices) that abuse the Windows Search protocol to launch Explorer and present a shortcut (LNK) pointing to a remote batch (BAT) script; the attack relies on social engineering and user interaction to trigger subsequent malware installation, highlighting a deceptive technique that evades basic email scanners and exploits familiar OS behaviors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
