CRON#TRAP Attack: Weaponized Linux VM Targets Windows Machines

A phishing email with a massive (285MB) ZIP attachment named “OneAmerica Survey.zip” tricks users, which contains a hidden folder “data” with the entire QEMU installation disguised as “fontdiag.exe.”  Clicking the shortcut “OneAmerica Survey.lnk” executes a PowerShell script that re-extracts the archive and runs a batch file “start.bat,” which  displays a fake “server error” and then … Continue reading CRON#TRAP Attack: Weaponized Linux VM Targets Windows Machines