Attackers used the legitimate Windows finger.exe utility in a phishing campaign to download and install the MineBridge backdoor, turning a rarely used Windows command into a living-off-the-land malware delivery tool. The lures arrived as malicious Word documents disguised as job applicant resumes, and victims who enabled editing or content triggered a password-protected macro that fetched a Base64-encoded payload from a remote server. The payload was written to %AppData%, decoded with certutil.exe, and executed, showing how multiple native Windows tools were chained together to avoid suspicion.
The downloader then retrieved a TeamViewer executable and used DLL hijacking to sideload MineBridge, ultimately giving the attackers broad remote access to infected systems. Reported capabilities included command execution, file download, process control, system information collection, and microphone access through TeamViewer. FireEye had previously linked MineBridge to phishing activity targeting South Korean organizations, indicating the campaign fit an established pattern of malware delivery and post-compromise remote control.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
SentinelLabs published technical analysis of a TA505 crypter, stating it had been used since at least September 2019 and that crypter overlap linked TA505 activity with Clop/CryptoMix tooling and with FireEye-reported MINEBRIDGE samples. The report also disclosed additional related malware, decoded command-and-control artifacts, sample hashes, domains, and YARA rules for detecting the packer.
Zscaler ThreatLabZ reported new MINEBRIDGE RAT instances discovered in January 2021, delivered through macro-enabled Word documents disguised as resumes and using finger.exe, certutil.exe, a self-extracting archive, and TeamViewer DLL side-loading. The report assessed with moderate confidence that the activity was likely conducted by TA505 based on similarities in lure themes and command-and-control infrastructure to earlier MINEBRIDGE operations.
FireEye previously reported numerous phishing campaigns targeting South Korean organizations that delivered the MineBridge malware and documented its remote-access capabilities.
Security researcher Kirk Sayre found a phishing campaign using malicious Word documents disguised as job applicant resumes to abuse Windows finger.exe, certutil.exe, and DLL hijacking to install the MineBridge backdoor.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 48 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
zscaler.com
Open sourcelabs.sentinelone.com
Open sourcebleepingcomputer.com
Open sourcefireeye.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.