Attackers are distributing Guloader malware through phishing emails that masquerade as employee performance reports, exploiting workplace trust and urgency to trick recipients into opening malicious attachments. The emails, purporting to be from HR or management and referencing October 2025 performance reviews, use psychological manipulation by suggesting potential dismissals, increasing the likelihood that employees will open the attached file. The attachment is a compressed archive containing an executable file disguised as a PDF (e.g., 'staff record pdf.exe'), which, if file extensions are hidden, appears innocuous but actually initiates a multi-stage infection process upon execution.
Once launched, the executable connects to a remote server—specifically a Google Drive URL—to download encrypted shellcode and further payloads. The infection chain ultimately leads to the deployment of Guloader, which can then download additional malware such as Remcos RAT, providing attackers with persistent access and control over the victim's system. This campaign leverages trusted cloud services to evade detection and highlights the ongoing evolution of social engineering tactics targeting organizations through familiar business processes and documents.

Get the infrastructure and lures behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Reporting on the campaign disclosed that Guloader uses a multi-stage, memory-resident infection chain, downloading encrypted shellcode or additional payload components from Google Drive to evade detection. The final Remcos RAT payload was observed communicating with command-and-control server 196.251.116.219 over ports 2404 and 5000.
AhnLab Security Intelligence Center (ASEC) reported a phishing campaign using fake October 2025 employee performance review emails, often with layoff-themed language, to trick recipients into opening a malicious archive. The attachment masquerades as a PDF but launches Guloader, which ultimately installs Remcos RAT for surveillance and credential theft.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcehackread.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.