The executable file displays the decoy document to the victim.
This document is written in English and appears to be legitimate, although CTU researchers were unable to locate the original source.
It describes the migratory pressure and asylum applications in countries that border Belarus (Lithuania, Latvia, and Poland) and discusses European Union (EU) sanctions against Belarus at the beginning of March 2022.
CTU researchers are unclear why a file with a Russian filename downloads an English-language document.
The other three files downloaded from the staging server are typical of the China-based BRONZE PRESIDENT threat group’s use of DLL search order hijacking to execute PlugX malware payloads.