logo

Malware Delivery via Cloud Services Exploits Unicode Trick to Deceive Users

ID: 5fdb468f-73ee-586c-bbbe-3e70670b85da

STIX ID: report--5fdb468f-73ee-586c-bbbe-3e70670b85da

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-05-21

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

CLOUD#REVERSER is a phishing-driven malware campaign that uses an executable disguised as an Excel file via the Unicode right-to-left override to trick victims. The payload drops obfuscated VBScript and PowerShell files that create scheduled-task persistence (masquerading as Chrome updates), download additional PowerShell scripts and binaries from Google Drive and Dropbox, and can execute payloads in memory to maintain C2 and exfiltrate data; the on-the-fly nature of the downloaded scripts allows actors to modify capabilities after compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.