Phishing campaign uses corrupted Word files to steal credentials

infosecurity-magazine.com

A new phishing campaign uses corrupted Microsoft Word documents to evade email security. It targets users with fake payroll and HR emails, enticing them to open malicious attachments that appear legitimate. The emails contain attachments with names like "Annual_Benefits_[name].docx" and "Q4_Benefits_[name].docx.bin." When opened, they trigger Word's recovery mode, leading users to scan a QR code. Scanning the code directs users to a fake Microsoft login page to steal credentials. Researchers at Any.Run discovered this tactic and shared their findings on social media last week.


With a significance score of 4, this news ranks in the top 5.9% of today's 31795 analyzed articles.

Get summaries of news with significance over 5.5 (usually ~10 stories per week). Read by 10,000+ subscribers:


Phishing campaign uses corrupted Word files to steal credentials | News Minimalist