Threat actors are distributing the Guloader malware through phishing emails disguised as employee performance reports. These emails claim to provide information about staff evaluations and potential dismissals, enticing recipients to open a compressed RAR file attachment. The archive contains an executable file named to appear as a PDF document, which, when run, deploys Guloader. This malware then downloads and executes shellcode from a remote server, ultimately installing Remcos RAT on the victim's system.
Remcos RAT enables attackers to perform a range of malicious activities, including keylogging, screenshot capture, webcam and microphone control, and the extraction of browser histories and passwords. The campaign leverages legitimate cloud storage services for command and control, increasing the difficulty of detection. Security researchers have provided indicators of compromise, such as specific MD5 hashes and C2 addresses, to aid in defense against this threat. Users are advised to exercise caution with unexpected emails and regularly update passwords to mitigate risk.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
AhnLab disclosed technical indicators for the campaign, including the malicious file MD5 hash c95f2a7556902302f352c97b7eed4159 and Remcos RAT command-and-control communications to 196.251.116.219 over ports 2404 and 5000. Additional indicators were made available through AhnLab TIP.
In the observed infection chain, executing the fake document launched Guloader, which retrieved shellcode from a Google Drive URL and loaded Remcos RAT. The RAT provided remote access and surveillance capabilities including keylogging, screenshot capture, webcam and microphone access, and credential theft.
A phishing campaign was identified that used emails about employee performance reports and possible dismissals to trick recipients into opening a malicious RAR attachment. The archive contained an NSIS executable named "staff record pdf.exe" disguised as a document.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.