{"id":9811,"date":"2026-01-12T10:03:42","date_gmt":"2026-01-12T10:03:42","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/12\/beware-of-weaponized-employee-performance-reports-that-deploys-guloader-malware\/"},"modified":"2026-01-12T10:03:42","modified_gmt":"2026-01-12T10:03:42","slug":"beware-of-weaponized-employee-performance-reports-that-deploys-guloader-malware","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/12\/beware-of-weaponized-employee-performance-reports-that-deploys-guloader-malware\/","title":{"rendered":"Beware of Weaponized Employee Performance Reports that Deploys Guloader Malware"},"content":{"rendered":"<p>    Beware of Weaponized Employee Performance Reports that Deploys Guloader Malware<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Cybersecurity threats continue to evolve with attackers using more creative social engineering techniques to target organizations. <\/p>\n<p>A recent threat has emerged involving the Guloader malware, which is being disguised as employee performance reports to trick users into downloading and executing malicious files. <\/p>\n<p>This sophisticated attack vector exploits human trust and workplace familiarity to distribute dangerous malware that can compromise sensitive company data and personal information.<\/p>\n<p>The attack begins with a phishing email claiming to contain an October 2025 employee performance report. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjp1-J7qpzdBOc6M21AnzwOtGaPLmYl17v5VZwd3HMZO-XoDMFDkjVGeTO5qozVV5I8s9tq1QPdv7YNQpDVN1wzFaCGa3ew3lyCRMAi2ZE4qh6H4B4C5Jht5MPXiGcB8gE_IW7FORycTiya6o6B3xrufEV1948QadR6hVb0XRK9qlj4e_cBvbm46D7IrRs\/s16000\/Phishing%2520email%2520body%2520%28Source%2520-%2520ASEC%29.webp?ssl=1\" alt=\"Phishing email body (Source - ASEC)\"><figcaption class=\"wp-element-caption\">Phishing email body (Source \u2013 ASEC)<\/figcaption><\/figure>\n<\/div>\n<p>The email uses urgency tactics by mentioning potential employee dismissals, prompting recipients to open the attachment. <\/p>\n<p>This psychological manipulation increases the likelihood of users bypassing <a href=\"https:\/\/cybersecuritynews.com\/security-awareness-in-2025-why-awareness-is-more-important-than-ever\/\" target=\"_blank\" rel=\"noreferrer noopener\">security awareness<\/a> and opening what appears to be a legitimate business document. <\/p>\n<p>The deceptive nature of this campaign makes it particularly dangerous, as it targets the intersection of workplace communication and security vulnerability.<\/p>\n<p>ASEC analysts and researchers <a href=\"https:\/\/asec.ahnlab.com\/en\/91825\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">noted<\/a> that the attached file is a RAR compressed archive containing an NSIS executable file disguised as \u201cstaff record pdf.exe\u201d. <\/p>\n<p>If users have file extensions hidden in their operating system settings, this executable appears as a standard PDF document. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgFBYe6rQT1rTsOsKKJ4WMNDzh7uy-8bUdO59iQVgr4Xoy89_VolEOjbf4sgK7DEAeAXSZD-vhnUI_ubIjm4Yb6bTdK090PWTcUdPBmHsfFt9thn8Kk4VFC6B_q8L_hK_-E9ecQnZqlaRqpVvOwglr69u47U-GN3o5041tOeGQ5gddXc71bc7K4kxjqXLw\/s16000\/Inside%2520the%2520attached%2520compressed%2520file%2520%28Source%2520-%2520ASEC%29.webp?ssl=1\" alt=\"Inside the attached compressed file (Source - ASEC)\"><figcaption class=\"wp-element-caption\">Inside the attached compressed file (Source \u2013 ASEC)<\/figcaption><\/figure>\n<\/div>\n<p>Once executed, the <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-powered-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> initiates a multi-stage infection process designed to evade detection and establish persistent access to the victim\u2019s system.<\/p>\n<h2 class=\"wp-block-heading\" id=\"the-multi-stage-infection-mechanism\"><strong>The Multi-Stage Infection Mechanism<\/strong><\/h2>\n<p>Understanding how Guloader operates reveals the sophisticated nature of this attack. <\/p>\n<p>When the executable runs, it connects to a remote server and downloads encrypted shellcode from a Google Drive URL, specifically from \u201chxxps:\/\/drive.google[.]com\/uc?export=download&amp;id=1bzvByYrlHy240MCIX7Cv41gP9ZY3pRsgv\u201d and retrieves a file named \u201cEMvmKijceR91.bin\u201d. <\/p>\n<p>The downloaded shellcode is then injected directly into the system\u2019s memory, allowing the malware to run without writing files to disk. <\/p>\n<p>This memory-only execution technique makes detection significantly more challenging for traditional security solutions that rely on file-based scanning.<\/p>\n<p>The final payload delivered by Guloader is <a href=\"https:\/\/cybersecuritynews.com\/threats-delivering-remcos\/\" target=\"_blank\" rel=\"noreferrer noopener\">Remcos RAT<\/a>, a remote access trojan that provides attackers with comprehensive control over infected systems. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgsRQpdhENXXaCkIKPI7udMf8OpqYLVPPJo__XDtxf9dUQKfJxX-N2muiO9a9ODvNPzp7N1ondT8RAGoFOivR9B0NiWAFnYXtY1UfUFfbDMJhihq7JQqhOx7GsBTg34fRVBZjN2QI4xYjOhyphenhyphen0gmOPfgMntAQREeWSG68ss2QdM4w7FJx4wnOJU0HW0fAII\/s16000\/C2%2520information%2520of%2520Remcos%2520RAT%2520%28Source%2520-%2520ASEC%29.webp?ssl=1\" alt=\"C2 information of Remcos RAT (Source - ASEC)\"><figcaption class=\"wp-element-caption\">C2 information of Remcos RAT (Source \u2013 ASEC)<\/figcaption><\/figure>\n<\/div>\n<p>Remcos enables threat actors to perform <a href=\"https:\/\/cybersecuritynews.com\/north-korean-hackers-using-malicious-scripts-combining-beavertail-and-ottercookie-for-keylogging\/\" target=\"_blank\" rel=\"noreferrer noopener\">keylogging<\/a>, capture screenshots, control webcams and microphones, and extract browser histories along with stored passwords. <\/p>\n<p>The malware communicates with command and control servers located at \u201c196.251.116[.]219\u201d on ports 2404 and 5000, establishing a persistent connection for ongoing unauthorized access. <\/p>\n<p>Organizations should implement email filtering rules to block suspicious attachments, disable file extension hiding in user systems, and deploy advanced <a href=\"https:\/\/cybersecuritynews.com\/best-edr-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">endpoint detection<\/a> and response solutions to identify and block this threat at multiple stages of the attack chain.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/beware-of-weaponized-employee-performance-reports\/\">Beware of Weaponized Employee Performance Reports that Deploys Guloader Malware<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/beware-of-weaponized-employee-performance-reports\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Beware of Weaponized Employee Performance Reports that Deploys Guloader Malware Cybersecurity threats continue to evolve with attackers using more creative social engineering techniques to target organizations. A recent threat has emerged involving the Guloader malware, which is being disguised as employee performance reports to trick users into downloading and executing malicious files. This sophisticated attack [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-9811","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9811"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9811"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9811\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9811"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9811"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9811"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}