Hackers are using fake Chrome, Word and OneDrive errors to trick people into installing malware


Proofpoint has observed an increase in a technique leveraging unique social engineering that directs users to copy and paste malicious PowerShell scripts to infect their computers with malware.

Threat actors including initial access broker TA571 and at least one fake update activity set are using this method to deliver malware including DarkGate, Matanbuchus, NetSupport, and various information stealers. Whether the initial campaign begins via malspam or delivered via web browser injects, the technique is similar. Users are shown a popup textbox that suggests an error occurred when trying to open the document or webpage, and instructions are provided to copy and paste a malicious script into the PowerShell terminal, or the Windows Run dialog box to eventually run the script via PowerShell.

Read more…
Source: Proofpoint


Sign up for our Newsletter


Related:

  • Uber Freight reportedly investigating after hacking group claims data breach

    August 12, 2026

    A hacking and extortion gang has taken credit for a cyberattack and data breach at Uber Freight, the ridesharing giant’s logistics subsidiary. A spokesperson for Uber Freight told Reuters, which first reported the incident, that there was no effect on its business operations and that its systems were running normally. (The company did not immediately respond to ...

  • The CEVA Logistics data breach is having major knock-on effects across Europe – here’s what we know

    August 11, 2026

    CEVA Logistics, one of the biggest shipping and logistics companies in the world, has suffered a major cyberattack, the effects of which are trickling down to many of its clients. The details of the hack itself, however, are not yet publicly available and what little information is out there came from the affected clients themselves. CEVA has ...

  • Fake CCleaner installs GhostDesk Chrome spyware

    August 11, 2026

    A fake version of the popular PC cleaning tool CCleaner is being used to infect Windows users with a malicious Chrome extension called GhostDesk, which acts as spyware inside the browser. With more than 2 billion downloads worldwide, CCleaner is one of the best-known Windows utilities, making it an attractive target for cybercriminals looking to distribute ...

  • Attackers pick Levi’s pockets in social engineering attack

    August 10, 2026

    Levi Strauss is investigating a data breach after attackers used social engineering to access three employees’ work computers. In a regulatory filing, the jeans maker said the intruders accessed and exfiltrated what it described only as “certain corporate information.” Levi’s said it spotted the intrusion, kicked off its incident response procedures, brought in outside cybersecurity experts, and managed ...

  • StopRansomware: Gunra Ransomware

    August 10, 2026

    Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom ...

  • Top US hedge funds targeted by major vishing campaign

    August 9, 2026

    Some of the biggest US hedge funds and law firms have been targeted by a highly sophisticated data breach and extortion campaign, conducted by a group of criminals previously known as BlackFile, experts have warned. BlackFile (or Redact, as the group is now calling itself) has a relatively simple modus operandi, also used by ShinyHunters – ...