الرئيس التنفيذي
أشرف الحادي

رئيس التحرير
فاطمة مهران

Deceptive docs: Attackers target employees with fake HR updates

Kaspersky has identified an advanced phishing campaign targeting employees with personalized emails and attached documents disguised as HR policy updates. This campaign marks a significant escalation in phishing tactics, with attackers tailoring not only the email body, but also the attachments by addressing individual recipients, showcasing an unprecedented level of customization. The goal was to lure the victim into entering their corporate email credentials.
The attackers likely prepared by parsing employee names to make the campaign targeted and more convincing. The emails feature a deceptive body: a fraudulent “verified sender” badge to build trust, the recipient’s name, and an invitation to open the attached file to review remote work protocols, benefits administration and security standards. However, the whole email body is in reality just an image with no real text in it; this is done to bypass email filters.

The body of the fraudulent email is made of an image, not text
The attached document, posing as an updated “Employee Handbook,” does not contain any actual guidelines – only a title page, a table of contents with the items that have supposedly been changed highlighted in red, a page with a QR code, supposedly for going to the full document and common instructions on how to read QR codes using a phone. The document features the victim’s name multiple times to convince that this document was created specifically for them.

The alleged “Employee handbook” attached file
If the victim scans the QR code and follows the link, they land on a fraudulent page where they are asked to enter their corporate credentials, which is what the attackers are hunting for.
“This campaign demonstrates a new level of sophistication in phishing attacks, and we may be seeing a new mailing automation mechanism that generates a separate attached document and a separate image for the email body for each recipient. This tactic allows to scale the attack and at the same time possibly evade traditional defenses. Organizations must prioritize advanced security measures and employee education to stay ahead of these threats,” comments Roman Dedenok, Anti-Spam Expert at Kaspersky.
To stay safe, Kaspersky recommends:
● Utilize specialized security solutions at the corporate mail server level to detect and block phishing attempts.
● Ensure all employee devices, including smartphones, are equipped with robust security software.
● Conduct regular training on modern phishing tactics.
● Encourage employees to scrutinize emails for signs of phishing, such as image-based text or mismatched document titles, and to verify requests directly with HR.

Related Posts:

OPPO Unveils Flagship Find X9 Pro and Comprehensive IoT Ecosystem at Cairo ICT 2025

Huawei at Cairo ICT 2025: Smart Solutions for Egypt’s Future

Central Bank of Egypt Participates in the 12th Edition of the Digital Payments, Financial Inclusion, and Digital Banking (PAFIX) International Conference and Exhibition

Raya Holding Reports Record-Breaking Results for Q3 and 9M 2025

Kaspersky reports 10% sales, highlights rising password stealers and spyware in the Middle East

Egypt Trust Launches a Series of Interactive Sessions and workshops at CAIRO ICT 2025

Heart of Hong Kong is Transformed into Winter Wonderland with Eight Iconic Buildings used as Canvas for New Immersive Lights Show

Reportage Properties expect Sales Exceeding SAR 500 Million by End of 2025

آخر الأخبار
رئيس الوزراء يستمع لعرض تقديمي حول مشروعات وزارة الاتصالات في مجال التحول الرقمي OPPO Unveils Flagship Find X9 Pro and Comprehensive IoT Ecosystem at Cairo ICT 2025 خطوات استخراج فيش جنائي مستعجل 2025 في 10 دقائق كيفية استخدام سجل عقارات الدولة الإلكتروني 2025 شركة eFinance تكشف «قفزة رقمية».. والرقابة المالية تطلق منصات جديدة في يناير Huawei at Cairo ICT 2025: Smart Solutions for Egypt’s Future "رئيس البريد يستعرض أمام رئيس الوزراء تطوير الخدمات وإطلاق الخدمات المالية الرقمية" وزيرة التضامن تزور المقر الرئيسي لبنك ناصر الاجتماعي .. وتتفقد سير العمل بداية قوية لـ Cairo ICT في دورته التاسعة والعشرين مصر تعيد رسم خريطة «سيادة البيانات» لحماية الخصوصية وتحفيز الابتكار "يوتن" تؤكد امتثالها القانوني والتزامها بالشفافية في إجراءات زيادة رأس المال الإمارات تتألق في أولمبياد الروبوتات وتحصل على المركز الأول بين 193 دولة انعقاد أول اجتماع بين جهاز الأموال المستردة وجمعية المطورين العقاريين لبحث آليات التعاون رسميًا.. محمد صلاح بالقائمة النهائية لجائزة أفضل لاعب فى أفريقيا استعلام تكافل وكرامة 2025 بالرقم القومي طريقة حجز عيادات التأمين الصحي أونلاين في مصر 2025 Oppo Find X9 Pro: المواصفات الكاملة والسعر المتوقع 2025 تقسيم مناطق الإيجار القديم في مصر: خريطة كاملة وتحديثات 2025 أسعار شقق ديارنا 2025: أحدث تحديثات الأسعار ومواصفات الوحدات البنك المركزي يشارك في المؤتمر والمعرض الدولي الثاني عشر للمدفوعات الرقمية والشمول المالي والبنوك ال...