Skip to content
Boeing RFQ Malware Campaign Exploits DOCX, RTF, JS, and Python

Boeing RFQ Malware Campaign Exploits DOCX, RTF, JS, and Python

First seen 2 Apr 2026, 15:33 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •April 3, 2026 at 15:31 UTC
  • •The NKFZ5966PURCHASE campaign targets procurement teams by impersonating Boeing.
  • •Attack methods include DOCX, RTF, JS, and Python to deliver Cobalt Strike beacons.
  • •The campaign employs living-off-the-land techniques and reuses encryption keys for evasion.

A sophisticated malware campaign, tracked as NKFZ5966PURCHASE, is targeting industrial suppliers and procurement teams by impersonating Boeing in procurement emails. The attack utilizes DOCX, RTF, JavaScript, PowerShell, and Python to deliver an in-memory Cobalt Strike beacon through a six-stage process. Victims are lured into opening a malicious Word document disguised as a Request for Quotation from a fake sender named Joyce Malave. This campaign leverages living-off-the-land binaries and reuses encryption keys across samples, enhancing its evasion capabilities. The exact number of affected organizations is currently unknown, but the operation poses a significant threat to supply chain security. As of now, the campaign is active and ongoing, with security professionals urged to remain vigilant.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 190d ago How this analysis works

Timeline

2026-04-02
Gbhackers and Cybersecuritynews publish articles on the malware campaign.

More articles in this cluster (2)

Following this threat?

Track Cobalt Strike in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed