216.73.216.36

Guloader Malware Being Disguised as Employee Performance Reports

· Published 08/01/2026 18:12 · Modified 09/01/2026 09:36

Export JSON

Essential information

Published
08/01/2026 18:12
Modified
09/01/2026 09:36
Tags
2026-01-08 guloader infostealer phishing remcos rat shellcode
Related entities
2 observables, 2 malware

Description

ASEC discovered malware being distributed through emails masquerading as employee performance reports. The emails, claiming to be about October 2025 performance, contain a RAR file with an NSIS executable named 'staff record pdf.exe'. This file is actually malware, which downloads and executes from a Google Drive URL. The final payload is , enabling threat actors to perform various malicious remote control activities, including keylogging, screenshot capture, webcam and microphone control, and browser data extraction. The attackers are increasingly using legitimate platforms as C2 servers, making detection more challenging. Users are advised to exercise caution when opening emails from unknown sources and to change passwords regularly to prevent secondary damage.

External references