Lure theme
Corrupted document or repair prompt
A shared-document link that lands on a viewer page claiming the file is damaged, encoded incorrectly, or missing a component, with a manual repair offered as the fix. This is the workplace variant: it arrives with a sender, a subject line and a reason to exist, so it is judged against the dozen legitimate document links the recipient opened that week rather than against the open web.
- First reported
- 2024-11
- Targets
- Windows
- Campaigns on record
- 2
Approximate. Document-repair pretexts follow the technique into email-delivered phishing from late 2024.
Also reported as Fake document viewer error · File is damaged lure · Fake cloud document viewer · Fake PDF repair
What a victim sees
A page dressed as a cloud document viewer, sometimes with the recipient's own email address already filled in to raise plausibility. Behind a blurred or greyed preview, a banner reports that rendering failed and offers a repair procedure. The instructions are framed as IT process — occasionally with an invented support-article reference or ticket number — and the tone is bureaucratic rather than urgent, which is exactly what makes it fit its surroundings.
Described rather than shown. This site publishes no screenshots of lure pages and reproduces none of their markup, because a working copy of a fake verification page is a fake verification page regardless of why it was made.
The tell-tale sign
Repairing a document is something a document application does. Word, Excel, Adobe Reader and every cloud viewer repair files from inside themselves. None of them has ever needed the operating system's Run dialog to open a file.
The underlying rule is the same for every theme on this site, and it is the one worth remembering: no legitimate website will ever ask you to press Windows+R, to open Terminal, or to paste anything into either one. Why that rule holds.
Campaigns using this lure
UNK_RemoteRogue using Empire
Status as last assessed: DormantA suspected Russian cluster Proofpoint labels UNK_RemoteRogue sent ten messages with no subject line on 9 December 2024, to people at two firms tied to a large defence manufacturer. The mail travelled through hacked Zimbra servers, which supplied the sender addresses, and carried a link on a domain imitating Microsoft's online office suite, with Ukrainian text describing it. Visiting the link produced a page mocked up as a Word document, with Russian instructions telling the reader to copy code out of the browser into a terminal; a YouTube tutorial on running PowerShell was linked for anyone unsure. What ran was JavaScript, which in turn launched PowerShell tied to the Empire post-exploitation framework. Proofpoint saw the group try this once, then revert to its usual approach: by late January 2025 that meant sending RDP configuration files mapping every local drive to a remote host.
ID d48c97cdFirst seen 2024-12-09Last seen 2024-12-09WindowsDarkGate from Storm-1607 mail
Status as last assessed: DormantThe earliest use of this technique Microsoft records in email ran from March to June 2024 and is attributed to the group it tracks as Storm-1607. A single run in May 2024 sent tens of thousands of messages to organisations across the United States and Canada, dressed as payments or invoices, with an HTML file attached under names of the shape reports_528647.html. Opening the attachment drew a mock-up of a fresh Word document, overlaid by an error box offering to put the problem right. Pressing that button quietly loaded a command onto the clipboard; the box then changed to explain how to open Windows Terminal and paste it in. The payload was DarkGate, a commodity loader that logs keystrokes, mines coins, talks to a controller and fetches more malware. Microsoft says attaching the lure has since given way to a link pointing at a hosted page.
ID 1e32ad6eFirst seen 2024-03-01Last seen 2024-05-28Windows