Boeing RFQ Malware Campaign Exploits DOCX, RTF, JS, and Python

Boeing RFQ Malware Campaign Exploits DOCX, RTF, JS, and Python

First seen 2 Apr 2026, 15:33 UTC GbhackersCybersecuritynews 66.5

Article Content

Browse articles
ThreatCluster

A sophisticated malware campaign, tracked as NKFZ5966PURCHASE, is targeting industrial suppliers and procurement teams by impersonating Boeing in procurement emails. The attack utilizes DOCX, RTF, JavaScript, PowerShell, and Python to deliver an in-memory Cobalt Strike beacon through a six-stage process. Victims are lured into opening a malicious Word document disguised as a Request for Quotation from a fake sender named Joyce Malave. This campaign leverages living-off-the-land binaries and reuses encryption keys across samples, enhancing its evasion capabilities. The exact number of affected organizations is currently unknown, but the operation poses a significant threat to supply chain security. As of now, the campaign is active and ongoing, with security professionals urged to remain vigilant.

Key Points: • The NKFZ5966PURCHASE campaign targets procurement teams by impersonating Boeing. • Attack methods include DOCX, RTF, JS, and Python to deliver Cobalt Strike beacons. • The campaign employs living-off-the-land techniques and reuses encryption keys for evasion.

Timeline

2026-04-02
Gbhackers and Cybersecuritynews publish articles on the malware campaign.