A fake student resume is being used to place a remote-access tool on researchers’ Windows computers. The campaign hides a Windows executable inside an archive that appears to contain a graduate-school application, then opens a genuine Word document while the infection runs quietly in the background.
The malicious ZIP archive uses a Chinese-language name that presents its supposed author as Zhang Yuguang, a network-engineering graduate. Inside is an executable with a near-identical document-style name, relying on Windows hiding known file extensions by default.