Seqrite Exposes Sophisticated XELERA Ransomware Operation Targeting Indian Tech Job Seekers Through FCI Impersonation
itvoice.inSeqrite, the enterprise security arm of Quick Heal Technologies Limited, a global cybersecurity solutions pro, has revealed critical details about an advanced ransomware campaign targeting technology professionals in India. Dubbed “XELERA,” the operation leverages fake job offers impersonating the Food Corporation of India (FCI) to infiltrate victims’ systems, marking a concerning evolution in social engineering tactics.
Researchers at Seqrite Labs, India’s largest malware analysis facility, noted that the attack begins with spear-phishing emails containing a malicious Word document titled FCEI-job-notification.doc. Disguised as an official FCI recruitment notice, the document outlines fabricated job vacancies for technical roles. Embedded within it is a compressed PyInstaller executable (jobnotification2025.exe) that bypasses traditional security defenses. Upon execution, the malware deploys Python-compiled scripts (mainscript.pyc) to establish persistent access, utilizing libraries like psutil and aiohttp for system monitoring and network communication.
A distinctive feature of XELERA is its integration with a Discord bot ...
Copyright of this story solely belongs to itvoice.in . To see the full text click HERE