Files with TXZ extension used as malspam attachments
Essential information
- Published
- 28/05/2024 10:59
- Modified
- 28/05/2024 11:28
- Tags
- 2024-05-28 formbook guloader malspam
- Related entities
- 2 observables, 10 techniques (mitre), 2 malware, 4 others
Description
A recent report describes a malspam campaign distributing malware payloads in attachments with TXZ file extensions. The attachments were RAR archives with renamed extensions, likely attempting to exploit native TXZ support in Windows 11. Two campaigns distributed the payloads, one with GuLoader malware targeting Spain and Slovakia, the other with Formbook targeting Croatia and Czechia.