Fake Employee Performance Reports Deliver Guloader Malware
## Cybersecurity: Phishing Campaign Alert
Cybersecurity: Phishing Campaign Alert
Organizations are advised of a phishing campaign leveraging fake employee performance reports to distribute Guloader malware, which subsequently installs Remcos RAT on compromised systems.
Threat actors are disseminating phishing emails claiming to include an employee performance report for October 2025. The emails suggest potential dismissals, urging recipients to review the attached report. This tactic exploits job security concerns to prompt users to open the attachment without scrutiny.
The attachment is a compressed RAR archive containing an NSIS executable named “staff record pdf.exe”.
The naming aims to mislead users into perceiving the file as a benign PDF, especially on systems with hidden file extensions. Upon execution, the file initiates the malware infection process.
Threat actors are disseminating phishing emails claiming to include an employee performance report for October 2025.
The “staff record pdf.exe” is the Guloader malware. When executed, it loads shellcode into memory and retrieves the next-stage payload from a remote command-and-control (C2) location. In this case, the shellcode is downloaded from a Google Drive URL.
Leveraging a legitimate cloud storage platform aids attackers in blending with normal traffic and avoiding simple domain-based blocking.
The final payload is Remcos RAT, a remote access trojan, providing attackers with extensive remote control capabilities. This includes logging keystrokes, capturing screenshots, and accessing webcams and microphones. In the reported incident, Remcos connected to its C2 server at 196.251.116[.]219 over ports 2404 and 5000.
Organizations should ensure the visibility of file extensions by default, provide continuous phishing awareness training, and implement advanced email and endpoint security solutions capable of detecting malicious activities.
Users are advised to treat unsolicited performance reports or HR-related documents with caution, especially those involving compressed archives or executable files. Regular password changes, multi-factor authentication, and prompt incident reporting can limit the impact of compromised credentials or infected systems.
Based on reporting by GBHackers.
