logo

Novel phising campaign uses corrupted Word documents to evade security

ID: a1eddbf2-f7b6-538e-836d-9f5fd7cf782a

STIX ID: report--a1eddbf2-f7b6-538e-836d-9f5fd7cf782a

Feed Name: Bleeping Computer

Threat Score
50/100

Date Published: 2024-12-01

Date Updated: 2026-03-27

Author: Lawrence Abrams

...
...

A phishing campaign uses intentionally corrupted Microsoft Word attachments that prompt Word's repair feature to display a QR code; victims who scan the code are directed to a fraudulent Microsoft login page to harvest credentials. The malformed files frequently evade security scanners and VirusTotal detections because they cannot be properly analyzed, making this a novel evasion technique.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.