logo

Phishing emails abuse Windows search protocol to push malicious scripts

ID: 59b4d748-1ba7-5c1e-9d3e-7fd8df25a13b

STIX ID: report--59b4d748-1ba7-5c1e-9d3e-7fd8df25a13b

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2024-06-12

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A phishing campaign uses HTML attachments (inside small ZIPs) that leverage the Windows Search protocol (search-ms URI) to point Explorer at attacker-controlled, Cloudflare-tunneled file shares; the search displays a fake invoice LNK that, if clicked, executes a BAT hosted by the remote server. Trustwave observed this technique in the wild, couldn't retrieve the payload (server was down), and recommends careful mitigation such as removing search-ms/search protocol registry entries, noting this may break legitimate functionality.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.