News
There are fake Word docs going around that contain almost undetectable malware

- July 7, 2022
- Updated: July 2, 2025 at 3:35 AM

Another malware scam has popped up that is hiding malicious files inside of seemingly legitimate files. Also, in a callback to the fake job offers that contained malware, which we reported on a while back, this scam is hidden inside infected Microsoft Word docs that are pretending to be legitimate CVs. Here is what you need to look out for.
Researchers at threat intelligence specialists Unit 42 based at Palo Alto Networks first spotted a threat back in May and have since been analyzing and breaking down the threat it represents. They say that the malicious payload was created using a tool called Bruce Ratel (BRC4), which incredibly has its own website where it is sold. The site describes the tool as, “A Customized Command and Control Center for Red Team and Adversary Simulation.”
This particular scam starts with a seemingly innocuous CV of a guy named Roshan Bandara. Straight away though, there are warning signs that should make potential victims stop and think. Unusually, the CV comes in the form of an ISO file, which is a disk image file and it is only after users have clicked on it that they can see the fake Word doc with the title “Roshan-Bandara_CV_Dialog”. When users click on this it opens up CMD.EXE and runs the OneDrive updater to retrieve and install BRC4.
BRC4 then goes on to perform many malicious actions on the victim’s devices, which anybody who has read our malware reports before will be familiar with. For Unit 42, however, what is most eye-catching about this form of attack is the method used to pull it off, they say:
“This tool is uniquely dangerous in that it was specifically designed to avoid detection by endpoint detection and response (EDR) and antivirus (AV) capabilities. Its effectiveness at doing so can clearly be witnessed by the aforementioned lack of detection across vendors on VirusTotal.”
This means that this new threat is able to get past over 50 different antivirus programs undetected, meaning you won’t get any sort of automated warning if it gets onto or near your device. You will be your main line of defense against this threat as most antivirus programs won’t even know it is there. To help you stay safe we have put together an infographic to help you spot fake files like this one.
Image via: Unit 42
Patrick Devaney is a news reporter for Softonic, keeping readers up to date on everything affecting their favorite apps and programs. His beat includes social media apps and sites like Facebook, Instagram, Reddit, Twitter, YouTube, and Snapchat. Patrick also covers antivirus and security issues, web browsers, the full Google suite of apps and programs, and operating systems like Windows, iOS, and Android.
Latest from Patrick Devaney
You may also like
- News
The infinite canvas: use of Generative Expand for print bleeds and concept exploration
Read more
- News
James Gunn clarifies the future of Harley Quinn after years of being a DC icon
Read more
- News
South Korea has grown in streaming much more than expected. They have to thank themselves
Read more
- News
One of the most controversial (and brave) artists in history will have her own biopic
Read more
- News
We have been waiting 15 years for the end of one of the best mangas in history. And now, finally, it is going to arrive
Read more
- News
Thunderbolts is coming to Disney+ sooner than you thought: This will be the release date on the platform
Read more