logo

That “job brief” on Google Forms could infect your device

ID: 380f6547-6e5d-5e91-85c1-998edbb7375f

STIX ID: report--380f6547-6e5d-5e91-85c1-998edbb7375f

Feed Name: Malwarebytes Blog

Threat Score
75/100

Date Published: 2026-03-20

Date Updated: 2026-04-28

...
...

This report describes an active campaign that uses convincing Google Forms (often promoted via LinkedIn) to host links to ZIP archives containing malicious payloads which ultimately deploy the PureHVNC RAT. The chain abuses DLL sideloading, obfuscated Python scripts that load Donut shellcode, and process injection to achieve persistence and exfiltrate browser data and cryptocurrency wallets; the report includes C2 details, URLs and multiple file hashes, plus defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.