AhnLab (053800.KQ), a South Korean cybersecurity firm, warned on the 24th that it had discovered phishing emails distributing malware disguised as employee performance reports. The attack exploits the year-end period when HR-related emails are frequent and employees' vigilance tends to be lower.
According to AhnLab, attackers recently impersonated corporate HR departments and sent emails with the subject line "Employee Performance Report."
The attackers attached a file to the email body and wrote that names highlighted in red indicated employees scheduled for termination. The attachment was named "Employee Records pdf," hiding its actual .rar extension to make it appear as a regular PDF document.
When users open the attachment, a compressed file is downloaded containing an executable file. Running this file activates remote-control malware capable of various malicious activities, including capturing PC screens, collecting keystrokes, accessing webcams and microphones, and stealing information stored in web browsers.
To prevent phishing-related damage, users should verify the validity of sender email domains, avoid executing attachments and URLs from unverified sources, apply the latest security patches, and enable real-time antivirus monitoring.
"People should develop the habit of carefully checking email senders and content, and share suspected phishing cases with colleagues to prevent damage together," said Lim Moon-ju, manager of AhnLab's analysis team.






