Decoy Microsoft Word Documents Used to Deliver Nim-Based Malware
ID: 83a6ee98-cfb2-5ba7-8c28-c35de01a3513
STIX ID: report--83a6ee98-cfb2-5ba7-8c28-c35de01a3513
Feed Name: The Hacker News
A recent phishing campaign uses decoy Microsoft Word documents that prompt users to enable macros to install a Nim-language backdoor which enumerates processes and connects to actor-controlled C2 domains impersonating Nepali government infrastructure; several C2 hostnames were observed but are no longer accessible. The report also highlights related social engineering campaigns distributing the Python-based Editbot Stealer, ongoing use of DarkGate and NetSupport RAT via email and fake update lures, the use of traffic distribution systems (TDS) to filter victims, and at least one chain that weaponized CVE-2023-36025, with activity linked to known criminal groups like TA571 and TA577.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
