A sophisticated attack campaign is targeting organizations in East Asia, exploiting job application processes to infiltrate corporate networks. The attack begins with a phishing email disguised as a job application, containing a malicious Google Drive link. When clicked, the link initiates a complex infection chain, downloading a VHDX file with malicious components. This file includes a Windows shortcut that triggers the deployment of a downloader.
The downloader employs sophisticated techniques to identify infected devices, leveraging a legitimate web analytics tool to transmit unique device identifiers. The infection chain continues with the retrieval of additional malicious payloads from Bitbucket. These payloads include a backdoor called SpyGrace, which establishes communication with a command-and-control server. This enables attackers to steal files, load plugins, and execute arbitrary commands on infected systems.