Novel phishing campaign uses corrupted Word documents to evade security
ID: 4b77d2b8-a408-558b-9cae-6428f44ed8a1
STIX ID: report--4b77d2b8-a408-558b-9cae-6428f44ed8a1
Feed Name: Bleeping Computer
A phishing campaign is abusing Microsoft Word's file recovery feature by sending intentionally corrupted .docx/.docx.bin attachments that appear damaged to security scanners but are recoverable in Word; the repaired documents instruct recipients to scan a QR code which redirects to fake Microsoft login pages to harvest credentials. Samples include recurring filename patterns and a base64 marker ("IyNURVhUTlVNUkFORE9NNDUjIw" -> "##TEXTNUMRANDOM45##") and show almost no detections on VirusTotal, highlighting an evasion tactic.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
