Cybersecuritynews Boeing RFQ Malware Campaign Exploits DOCX, RTF, JS, and Python
Article Content
- •The NKFZ5966PURCHASE campaign targets procurement teams by impersonating Boeing.
- •Attack methods include DOCX, RTF, JS, and Python to deliver Cobalt Strike beacons.
- •The campaign employs living-off-the-land techniques and reuses encryption keys for evasion.
A sophisticated malware campaign, tracked as NKFZ5966PURCHASE, is targeting industrial suppliers and procurement teams by impersonating Boeing in procurement emails. The attack utilizes DOCX, RTF, JavaScript, PowerShell, and Python to deliver an in-memory Cobalt Strike beacon through a six-stage process. Victims are lured into opening a malicious Word document disguised as a Request for Quotation from a fake sender named Joyce Malave. This campaign leverages living-off-the-land binaries and reuses encryption keys across samples, enhancing its evasion capabilities. The exact number of affected organizations is currently unknown, but the operation poses a significant threat to supply chain security. As of now, the campaign is active and ongoing, with security professionals urged to remain vigilant.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Cobalt Strike in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
FamousSparrow Deploys SparroWocky Backdoor in Latin America The China-aligned cyberespionage group FamousSparrow has replaced its previous backdoor, SparrowDoor, with a new malware called SparroWocky, targeting governmental organizations in Latin America since August 2025. ESET Research attributes this campaign to a likely response to increased U.S. interests in the region.…
Emerging EDR Killer Tool Targeting Ransomware Groups A new malicious tool, referred to as the EDR killer, is being actively used by at least eight ransomware groups, including Blacksuit and Medusa, to disable endpoint detection and response (EDR) solutions. This tool is believed to be an evolution of the EDRKillShifter developed by RansomHub, which allows ransomware…