الرئيس التنفيذي
أشرف الحادي

رئيس التحرير
فاطمة مهران

Deceptive docs: Attackers target employees with fake HR updates

Kaspersky has identified an advanced phishing campaign targeting employees with personalized emails and attached documents disguised as HR policy updates. This campaign marks a significant escalation in phishing tactics, with attackers tailoring not only the email body, but also the attachments by addressing individual recipients, showcasing an unprecedented level of customization. The goal was to lure the victim into entering their corporate email credentials.
The attackers likely prepared by parsing employee names to make the campaign targeted and more convincing. The emails feature a deceptive body: a fraudulent “verified sender” badge to build trust, the recipient’s name, and an invitation to open the attached file to review remote work protocols, benefits administration and security standards. However, the whole email body is in reality just an image with no real text in it; this is done to bypass email filters.

The body of the fraudulent email is made of an image, not text
The attached document, posing as an updated “Employee Handbook,” does not contain any actual guidelines – only a title page, a table of contents with the items that have supposedly been changed highlighted in red, a page with a QR code, supposedly for going to the full document and common instructions on how to read QR codes using a phone. The document features the victim’s name multiple times to convince that this document was created specifically for them.

The alleged “Employee handbook” attached file
If the victim scans the QR code and follows the link, they land on a fraudulent page where they are asked to enter their corporate credentials, which is what the attackers are hunting for.
“This campaign demonstrates a new level of sophistication in phishing attacks, and we may be seeing a new mailing automation mechanism that generates a separate attached document and a separate image for the email body for each recipient. This tactic allows to scale the attack and at the same time possibly evade traditional defenses. Organizations must prioritize advanced security measures and employee education to stay ahead of these threats,” comments Roman Dedenok, Anti-Spam Expert at Kaspersky.
To stay safe, Kaspersky recommends:
● Utilize specialized security solutions at the corporate mail server level to detect and block phishing attempts.
● Ensure all employee devices, including smartphones, are equipped with robust security software.
● Conduct regular training on modern phishing tactics.
● Encourage employees to scrutinize emails for signs of phishing, such as image-based text or mismatched document titles, and to verify requests directly with HR.

Related Posts:

Visa Offers Priority Ticket Pre-Sale for the TotalEnergies CAF AFCON, Morocco 2025 for Cardholders

Rasha Khalifa Al Mubarak Participates in Congress of Arabic and Creative Industries Alongside Hend Sabry, Mariam Naoum, and Nadine Labaki

Mastercard collaborates with HyperPay to transform the region’s business payments landscape

Talaat Mostafa Group collaborate

Governor of the Central Bank of Egypt Attends the 49th Annual Meeting of the Council of Arab Central Banks and Monetary Authorities’ Governors in Tunisia

“Allianz Egypt Launches Insurance Awareness Campaign”

DP World Welcomes U.S. Ambassador to Egypt and Delegation of Leading American Companies at Sokhna Port

Dubai Land Department wins ‘Inspirational Brand Category’ award, reaffirming the emirate’s real estate leadership

آخر الأخبار
وزير التعليم يصدر قرارا وزاريا بشأن تطبيق نظام الدراسة والتقييم لطلاب المرحلة الثانوية كلام في الكورة مع " فراشة" قناة الزمالك نادين تيسير .. الثقافة ثم الجمال اساس نجاح اي مذيعة رياضية ظهور مبهر للنجمة التونسية يسرا مسعودي في نهاية الصيف الفيدرالى الأمريكى يخفض الفائدة على الدولار بنسبة 0.25% لتصل إلى 4.25% وزير الأوقاف يشهد الجلسة الافتتاحية للقمة الدولية الثامنة لزعماء الأديان بالعاصمة أستانا وزير الخارجية يلتقى مع نظيره الإسباني Visa Offers Priority Ticket Pre-Sale for the TotalEnergies CAF AFCON, Morocco 2025 for Cardholders فيزا تقدم أولوية لحاملي بطاقاتها للحصول علي تذاكر كأس الأمم الإفريقية توتال إنيرجي المغرب 2025 وزير الاستثمار يلتقى السفير الإيطالي بالقاهرة ووفد شركة تكنوكاب لبحث سبل تعزيز التعاون المشترك   وزير الإسكان يصدر حركة تغييرات بهيئة المجتمعات العمرانية وأجهزة المدن الجديدة سعد لمجرد لـ"أجمد 7": شرف لى الغناء باللهجة المصرية و"شبه دماغي" أغنية كلها فرح توزع أجهزة تعويضية لذوي الهمم مقدمة من مؤسسه مصر الخير بتمويل بنكQNB مصر فى محافظة المنيا  سعر ومواصفات ام جي 5 2026 في السوق المصري والخليجي كيفية الحصول على قرض المشروعات الصغيرة للسيدات من البنوك وخطوات التقديم منصة "تُــوم" تدفع عجلة التحول الرقمي في "بنك سنتر كريدت" لصياغة العمليات المصرفية  أليانز بمصر تستكمل حملتها التوعوية التي تستهدف رفع الوعي حول أهمية التأمين Rasha Khalifa Al Mubarak Participates in Congress of Arabic and Creative Industries Alongside Hend ... مؤسسة ساويرس للتنمية الاجتماعية "الشريك الداعم للأثر" لمهرجان الجونة السينمائي 2025 السياحة والآثار تؤكد عدم اختفاء أي قطعة أثرية بالمتحف اليوناني الروماني بالإسكندرية Mastercard collaborates with HyperPay to transform the region’s business payments landscape