Hey everyone, I recently read a report by AhnLab Security Intelligence Center about something that sounds kind of worrying. It involves fake employee performance reviews supposedly from October 2025 that are being used to trick staff into downloading malware like Guloader and Remcos RAT. The idea seems to be that people get scared about their jobs and click on a file that isn’t really a PDF but an executable.
What caught my attention is how these files hide in temporary memory and download additional tools from Google Drive, which apparently makes them harder to detect with basic security setups. The report even mentions that once active, Remcos RAT can monitor webcams, microphones, and keystrokes. It’s unsettling to think about how personal and work devices could be exposed this way.
I’m not entirely sure how widespread this is or if certain industries are more targeted, but it seems like a clever social engineering tactic. It got me thinking about what steps companies and individuals can take to spot something like this before it becomes a bigger issue.
Has anyone here come across similar email schemes or malware tactics? I’m curious about what the community thinks and how people are approaching protection beyond basic antivirus programs.