
Invoice Phish Leads to Resilient ValleyRAT
A Japanese industrial manufacturer was targeted by the SilverFox group using an invoice-themed phishing email that kicked off a multi-stage malware chain. The…
Researchers reported a targeted espionage operation against Bangladesh’s military and defense organizations using spear‑phishing emails with a booby‑trapped RTF document. When opened, the file pulls malicious content remotely and installs an implant that persists on the device while quietly sending data back to the attackers over encrypted web traffic.
This campaign, reported by Cyderes and attributed to the DoNot Team, targeted Bangladesh's military and defense establishments using spear-phishing emails containing a malware-laced RTF document. The lure asked recipients to review an attached RTF file, a simple and familiar request designed to lower suspicion among busy staff handling routine paperwork.
Once opened, the RTF used remote template injection to fetch a VBA macro. This macro then kicked off a multi-stage attack chain: shellcode execution, delivery of a DLL implant, and persistence achieved through a scheduled task disguised as OneDrive telemetry. The implant profiled the host and then beaconed to a command-and-control server over HTTPS, blending its traffic in with normal encrypted web activity.
A few design choices made this operation particularly effective:
Together, these choices reflect high attack sophistication, prioritizing stealth and precision targeting over broad, noisy distribution.
Defenders and staff in military, government, and defense-adjacent roles should be alert to:
Organizations in government, military, and defense sectors can reduce risk by training administrative and leadership staff to treat unsolicited document attachments as inherently risky, particularly RTF files that could trigger remote content retrieval. Staff should be encouraged to report suspicious attachments rather than open them, even when the message appears routine or plausible. Because this campaign used regional targeting and multi-stage payload delivery, awareness programs should emphasize that even normal-looking, role-relevant emails can carry hidden malicious document workflows, and that reporting first is always the safer choice.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
The RTF used remote template injection to fetch a VBA macro, which then triggered a multi-stage attack chain including shellcode, a DLL implant, and persistence disguised as OneDrive telemetry.
The campaign targeted Bangladesh's military and defense establishments, along with government employees and administrative staff who handle documents.
The attack used server-side geofencing to restrict payload delivery to victims located inside the target region, making the operation harder to detect broadly.
Treat unexpected RTF or document attachments as high risk, especially those that try to pull additional content from the internet or run embedded macros, and report them instead of opening them.
You get an email: "Action required: Please review the attached RTF document." Looks routine, right? But this RTF is weaponized. It uses remote template injection to pull a VBA macro, then quietly drops a DLL implant and sets a fake OneDrive telemetry scheduled task. Here’s the sneaky part: it uses geofencing to only deliver the real payload inside our region, then beacons over HTTPS so it just looks like normal web traffic. If you get an unexpected RTF attachment about sensitive work, do not open it, forward it to the security team and let them check it first.

A Japanese industrial manufacturer was targeted by the SilverFox group using an invoice-themed phishing email that kicked off a multi-stage malware chain. The…

FortiGuard Labs reports an active phishing operation (“TTF Trap”) where emails posing as invoices, shipping documents, or business proposals deliver an archive…

A real, ongoing phishing campaign is tricking recipients into opening malicious archives that appear to contain harmless TrueType font files (.ttf) but…

Investigators found evidence of a China-linked operation (tracked as JadeProx) targeting government, healthcare, and education organizations, including…

CERT-UA reports a real phishing campaign linked to Russia-aligned actor UAC-0099 targeting Ukrainian organizations. Victims receive an email with an image…

A real phishing campaign targeted Indian businesses and individual taxpayers by impersonating government departments and sending emails that look like official…