Proofpoint’s analysis revealed Bitter’s phishing emails with foreign investment project decoys, used to distribute a RAR archive containing a malicious shortcut link. When opened, it triggered a PowerShell execution and a scheduled task, initiating malicious curl commands, including one fetching the WmRAT.

Noodlophile Malware Campaign Expands Global Reach with Copyright Phishing Lures
The threat actors behind the Noodlophile malware are leveraging spear-phishing emails and updated delivery mechanisms to deploy the information stealer in attacks aimed at enterprises