216.73.217.22

XELERA Ransomware Campaign: Fake Food Corporation of India Job Offers Targeting Tech Aspirants

· Published 12/02/2025 10:20 · Modified 12/02/2025 12:35

Export JSON

Essential information

Published
12/02/2025 10:20
Modified
12/02/2025 12:35
Tags
2025-02-12 discord bot india job offer memz pyinstaller ransomware spear-phishing tech sector xelera
Related entities
4 observables, 2 malware, 3 others

Description

A newly discovered campaign is targeting tech job aspirants in using fake Food Corporation of job offers. The , written in Python and packed with , is distributed through emails containing malicious Word documents. The infection chain involves multiple stages, including a malicious OLE object, a executable, and Python scripts. The malware utilizes a for command and control, enabling various malicious activities such as credential theft, file exfiltration, and system disruption. The component, , not only encrypts data but also corrupts the Master Boot Record, making systems unbootable. The campaign demonstrates sophisticated social engineering tactics and multi-stage malware deployment, posing a significant threat to individuals and organizations in 's .

External references