The NewsPenguin threat actor targeted Pakistani manufacturing, government, and military sectors with a spear-phishing attachment that pretended to be an exhibitor manual for PIMEC-23.
The document utilized remote template injection and malicious Visual Basic for Applications (VBA) macro code to carry out the infection process.
The final payload was an undocumented espionage tool that bypassed sandboxes and exfiltrated data from the infected system.