{"id":196513,"date":"2022-07-07T09:17:05","date_gmt":"2022-07-07T07:17:05","guid":{"rendered":"http:\/\/sftarticles.wpenginepowered.com\/en\/?p=196513"},"modified":"2025-07-01T20:35:51","modified_gmt":"2025-07-02T03:35:51","slug":"fake-word-docs-contain-almost-undetectable-malware","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/fake-word-docs-contain-almost-undetectable-malware\/","title":{"rendered":"There are fake Word docs going around that contain almost undetectable malware"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Another malware scam has popped up that is hiding malicious files inside of seemingly legitimate files. Also, in a callback to the fake job offers that contained malware, which we reported on a while back, <strong>this scam is hidden inside infected Microsoft Word docs that are pretending to be legitimate CVs<\/strong>. Here is what you need to look out for.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"Microsoft Word\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-logo-xl,f_auto\/p\/b20c5e90-96bf-11e6-9781-00163ed833e7\/4112465458\/microsoft-word-microsoft_word_2019_16_icon.jpg\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Microsoft Word<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/microsoft-word.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">Download Now<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/microsoft-word.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Researchers at threat intelligence specialists Unit 42 based at Palo Alto Networks<strong> first <a href=\"https:\/\/unit42.paloaltonetworks.com\/brute-ratel-c4-tool\/#Conclusion\" target=\"_blank\" rel=\"noreferrer noopener\">spotted a threat<\/a> back in May<\/strong> and have since been analyzing and breaking down the threat it represents. They say that the <strong>malicious payload was created using a tool called Bruce Ratel (BRC4)<\/strong>, which incredibly has its own website where it is sold. The site describes the tool as, <em>\u201cA Customized Command and Control Center for Red Team and Adversary Simulation.\u201d<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This particular scam starts with a seemingly innocuous CV of a guy named Roshan Bandara. Straight away though,<strong> there are warning signs<\/strong> that should make potential victims stop and think. Unusually, <strong>the CV comes in the form of an ISO file<\/strong>, which is a disk image file and it is only after users have clicked on it that they can see the fake Word doc with the title <em>&#8220;Roshan-Bandara_CV_Dialog&#8221;<\/em>. When users click on this it opens up CMD.EXE and <strong>runs the OneDrive updater to retrieve and install BRC4.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>BRC4 then goes on to perform many malicious actions on the victim\u2019s devices<\/strong>, which anybody who has read our malware reports before will be familiar with. For Unit 42, however, what is most eye-catching about this form of attack is the method used to pull it off, they say:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>\u201cThis tool is uniquely dangerous in that it was specifically designed to avoid detection by endpoint detection and response (EDR) and antivirus (AV) capabilities. Its effectiveness at doing so can clearly be witnessed by the aforementioned lack of detection across vendors on VirusTotal.\u201d<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This means that <strong>this new threat is able to get past over 50 different antivirus programs undetected<\/strong>, meaning you won\u2019t get any sort of automated warning if it gets onto or near your device. You will be your main line of defense against this threat as most antivirus programs won\u2019t even know it is there. To help you stay safe we have put together an <a href=\"https:\/\/en.softonic.com\/articles\/how-to-detect-fakescam-emails-and-avoid-phishing-attacks-hi-res-version\" target=\"_blank\" rel=\"noreferrer noopener\">infographic to help you spot fake files like this one<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Image via: <a href=\"https:\/\/unit42.paloaltonetworks.com\/brute-ratel-c4-tool\" target=\"_blank\" rel=\"noreferrer noopener\">Unit 42<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Another malware scam has popped up that is hiding malicious files inside of seemingly legitimate files. Also, in a callback to the fake job offers that contained malware, which we reported on a while back, this scam is hidden inside infected Microsoft Word docs that are pretending to be legitimate CVs. Here is what you &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/fake-word-docs-contain-almost-undetectable-malware\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;There are fake Word docs going around that contain almost undetectable malware&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9073,"featured_media":196515,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":2},"categories":[1015],"tags":[3221],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-196513","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-app-subdomain-redirectionmicrosoft-word"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/196513","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9073"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=196513"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/196513\/revisions"}],"predecessor-version":[{"id":323562,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/196513\/revisions\/323562"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/196515"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=196513"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=196513"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=196513"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=196513"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=196513"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=196513"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}