Skip to main content

Novel phising campaign uses corrupted Word documents to evade security

  • December 2, 2024
  • 0 replies
  • 7 views

TripleHelix
Moderator
Forum|alt.badge.img+63

December 1, 2024

 

Phishing hook

A novel phishing attack abuses Microsoft's Word file recovery feature by sending corrupted Word documents as email attachments, allowing them to bypass security software due to their damaged state but still be recoverable by the application.

Threat actors constantly look for new ways to bypass email security software and land their phishing emails in targets' inboxes.

A new phishing campaign discovered by malware hunting firm Any.Run utilizes intentionally corrupted Word documents as attachments in emails that pretend to be from payroll and human resources departments.

Phishing email
Phishing email

Full Article