A new phishing campaign uses the lure of a job to infect victims with leaked versions of Cobalt Strike beacons. The Cobalt Strike beacon allows the threat actors to execute commands remotely on the infected device, allowing threat actors to steal data or spread laterally through the compromised network. Researchers said that the attack begins with phishing emails regarding fraudulent job opportunities with either the U.S. government or a trade union in New Zealand. The attacker tries to exploit CVE-2017-0199 a distant code execution vulnerability in Microsoft office.

US govt-themed phishing lure[/subscribe_to_unlock_form]
A new phishing campaign uses the lure of a job to infect victims with leaked versions of Cobalt Strike beacons. The Cobalt Strike beacon allows the threat actors to execute commands remotely on the infected device, allowing threat actors to steal data or spread laterally through the compromised network. Researchers said that the attack begins with phishing emails regarding fraudulent job opportunities with either the U.S. government or a trade union in New Zealand. The attacker tries to exploit CVE-2017-0199 a distant code execution vulnerability in Microsoft office.

US govt-themed phishing lure[emaillocker id="1283"]
References:
The following reports contain further technical details:
https://thehackernews.com/2022/09/new-malware-campaign-targeting-job.html
(Kindly exclude this link in the advisory mail)
https://blog.talosintelligence.com/2022/09/new-campaign-uses-government-union.html
[/emaillocker]