News
There are fake Word docs going around that contain almost undetectable malware
- July 7, 2022
- Updated: June 16, 2025 at 8:41 PM
Another malware scam has popped up that is hiding malicious files inside of seemingly legitimate files. Also, in a callback to the fake job offers that contained malware, which we reported on a while back, this scam is hidden inside infected Microsoft Word docs that are pretending to be legitimate CVs. Here is what you need to look out for.
Researchers at threat intelligence specialists Unit 42 based at Palo Alto Networks first spotted a threat back in May and have since been analyzing and breaking down the threat it represents. They say that the malicious payload was created using a tool called Bruce Ratel (BRC4), which incredibly has its own website where it is sold. The site describes the tool as, โA Customized Command and Control Center for Red Team and Adversary Simulation.โ
This particular scam starts with a seemingly innocuous CV of a guy named Roshan Bandara. Straight away though, there are warning signs that should make potential victims stop and think. Unusually, the CV comes in the form of an ISO file, which is a disk image file and it is only after users have clicked on it that they can see the fake Word doc with the title โRoshan-Bandara_CV_Dialogโ. When users click on this it opens up CMD.EXE and runs the OneDrive updater to retrieve and install BRC4.
BRC4 then goes on to perform many malicious actions on the victimโs devices, which anybody who has read our malware reports before will be familiar with. For Unit 42, however, what is most eye-catching about this form of attack is the method used to pull it off, they say:
โThis tool is uniquely dangerous in that it was specifically designed to avoid detection by endpoint detection and response (EDR) and antivirus (AV) capabilities. Its effectiveness at doing so can clearly be witnessed by the aforementioned lack of detection across vendors on VirusTotal.โ
This means that this new threat is able to get past over 50 different antivirus programs undetected, meaning you wonโt get any sort of automated warning if it gets onto or near your device. You will be your main line of defense against this threat as most antivirus programs wonโt even know it is there. To help you stay safe we have put together an infographic to help you spot fake files like this one.
Image via: Unit 42
Patrick Devaney is a news reporter for Softonic, keeping readers up to date on everything affecting their favorite apps and programs. His beat includes social media apps and sites like Facebook, Instagram, Reddit, Twitter, YouTube, and Snapchat. Patrick also covers antivirus and security issues, web browsers, the full Google suite of apps and programs, and operating systems like Windows, iOS, and Android.
Latest from Patrick Devaney
You may also like
- News
A Day in the Life of a Modern SMB Powered by Google Workspace
Read more
- News
After fighting for it, the fans have succeeded and Dying Light: The Beast has listened to them
Read more
- News
This game has excited and sold more than three million copies in just three days
Read more
- News
Star Trek: Strange New Worlds premieres its third season, but some creative ideas were left behind
Read more
- News
Look at the impressive transformation of Minecraft with this update
Read more
- News
He participated in one of the most iconic series on television, and he also had to fight for equal pay
Read more