XELERA Ransomware Campaign: Fake Food Corporation of India Job Offers Targeting Tech Aspirants

Feb. 12, 2025, 12:35 p.m.

Description

A newly discovered ransomware campaign is targeting tech job aspirants in India using fake Food Corporation of India job offers. The XELERA ransomware, written in Python and packed with PyInstaller, is distributed through spear-phishing emails containing malicious Word documents. The infection chain involves multiple stages, including a malicious OLE object, a PyInstaller executable, and Python scripts. The malware utilizes a Discord bot for command and control, enabling various malicious activities such as credential theft, file exfiltration, and system disruption. The ransomware component, XELERA, not only encrypts data but also corrupts the Master Boot Record, making systems unbootable. The campaign demonstrates sophisticated social engineering tactics and multi-stage malware deployment, posing a significant threat to individuals and organizations in India's tech sector.

Date

  • Created: Feb. 12, 2025, 10:20 a.m.
  • Published: Feb. 12, 2025, 10:20 a.m.
  • Modified: Feb. 12, 2025, 12:35 p.m.

Indicators

  • ff06ce3fd6fe994aeaa0edc5162989d08f34440e9cacbc9e49e5db8ef98a74e3
  • 519401c998fe5d6eb143415f7c17ad5f8e5ef5ebae57ac91e9fa89a0bfcf0c7f
  • http://chochox.com/wp-content/uploads/2016/10/Geto
  • thugging.org

Attack Patterns

  • MEMZ
  • XELERA

Additional Informations

  • Technology
  • British Indian Ocean Territory
  • India