A procurement-themed lure and a JavaScript payload are being used to probe US enterprises, with the malware described as a backdoor that seeks persistent access.
A procurement-themed .js attachment can become a foothold on Windows, showing how a routine inbox task can turn into execution, persistence, and remote control.
A business-themed email chain using RAR archives and in-memory execution shows how infostealers can slip from inbox to Windows endpoint without needing obvious malware theatrics.