logo

Decoy Microsoft Word Documents Used to Deliver Nim-Based Malware

ID: 83a6ee98-cfb2-5ba7-8c28-c35de01a3513

STIX ID: report--83a6ee98-cfb2-5ba7-8c28-c35de01a3513

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2023-12-22

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

A recent phishing campaign uses decoy Microsoft Word documents that prompt users to enable macros to install a Nim-language backdoor which enumerates processes and connects to actor-controlled C2 domains impersonating Nepali government infrastructure; several C2 hostnames were observed but are no longer accessible. The report also highlights related social engineering campaigns distributing the Python-based Editbot Stealer, ongoing use of DarkGate and NetSupport RAT via email and fake update lures, the use of traffic distribution systems (TDS) to filter victims, and at least one chain that weaponized CVE-2023-36025, with activity linked to known criminal groups like TA571 and TA577.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.