logo

That “job brief” on Google Forms could infect your device

ID: 7e6f72fd-4a6e-5de1-b3a5-e69619b60202

STIX ID: report--7e6f72fd-4a6e-5de1-b3a5-e69619b60202

Feed Name: Security Boulevard

Threat Score
72/100

Date Published: 2026-03-20

Date Updated: 2026-04-22

Author: Malwarebytes

...
...

Malicious actors are running a campaign that lures victims with business-related Google Forms linking to ZIP files hosted on common file-sharing services; those ZIPs contain executables and a malicious DLL that leverages DLL hijacking to start a multi-stage infection culminating in PureHVNC RAT deployment. The chain uses obfuscated Python and Donut shellcode, achieves persistence via registry keys and scheduled tasks, collects browser and crypto-wallet data, and communicates with listed C2 infrastructure; the report includes IPs, URLs, and multiple file hashes as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.