How a Fake Partnership Proposal Led to Malware Infection
HuFiCon Management Memo:
Journey with the CISO
A mountain climb to cyber security resilience. Find out how to get to the summit of cyber security resilience in Inge van der Beijl's management memo, from her presentation at the Human Firewall Conference (HuFiCon) on the 14.11.2024.
The climb will take you from the base camp of foundational security to the high-camp of a security conscious culture, all the way to the summit consisting of strategic security integration.
Inge van der Beijl
Director Innovation

Our SOC Investigation into a Sophisticated Social Engineering Attack
As social engineering and business email compromise (BEC) tactics become more targeted and sophisticated, trusted relationships can be exploited as a smooth pathway into organisations.
In an incident recently investigated by Northwave’s Security Operations Centre (SOC), a threat actor impersonated a popular brand and took extensive measures to convince an employee about a business partnership opportunity. This was far from a simple phishing lure. Rather, it was an elaborate scheme to build an trusted relationship with an employee and ultimately use proposal documents to smuggle malicious code into the organisation. Here’s what our SOC has uncovered about the incident and what you should know to avoid these convincing tactics.
How the attack worked
It all started when the threat actor initiated contact via the organisation’s website contact form. In follow-up communication, the threat actor used structured emails with detailed responses to the organisation’s questions. The victim then agreed to receive a link to a file with more information on a proposed partnership opportunity.
Since the link appeared to come from a well-known brand relevant to the organisation’s business context and the recipient believed they had vetted the sender, they forwarded the information to their colleagues. Fortunately, in this case, only the original recipient downloaded the files, not the colleagues who received the shared link.
Here’s how the attack unfolded:
-
The victim received the ZIP file that included a document, a shortcut, and a screensaver (.scr) file that indicated it contained documents related to the partnership proposal.
-
The document contained convincing text about the partnership and instructed the victim to open the screensaver file using a provided password, making it seem like a normal part of the proposal that offered the receiver additional information. The .scr file was signed by 'Postman, Inc.'
-
When the user opened the .scr file, it displayed a legitimate-looking PDF about the partnership. At the same time, in the background, the .scr file executed malicious code that:
-
- Gathered information about the victim.
- Injected itself into web browsers (Chrome, Edge, Firefox).
- Downloaded additional malware.
- Created persistence through a scheduled task. o Collected and exfiltrated data to attackers via Telegram.
Overall, the activity combined several defence evasion tactics and an impressive social engineering effort. We believe the threat actor used generative AI to help develop the messaging in the document and the website, making them seem authentic enough for the customer to initially challenge the SOC’s isolation decision. Reinstating the infected device enabled the malicious activity to resume before the device was ultimately wiped. The followed up injections into several browsers and C2 communication with api.telegram.com indicate it was a well-targeted attack.
Why a screensaver file?
- It’s really an executable file
- In Windows, screensaver files (.scr) are treated almost the same as .exe files.
- When a user double-clicks a .scr file, Windows runs it as a program.
- Many users don't recognise the risk
- Most people know that .exe files can be dangerous but don’t realise .scr files can also execute code.
- The attackers used legitimate-looking documents and instructions to make opening the .scr file seem normal.
- Can show a decoy while running malware
- The malicious screensaver displayed a convincing PDF about the partnership.
- Meanwhile, it secretly performed malicious actions in the background.
- This helps delay suspicion because the user sees what they expected to see.

What Organisations Can Learn From This Incident
Last year, BEC accounted for more than 40% of Northwave’s incident response cases, surpassing cyber extortion. As we detailed in our Global Threat Landscape Report 2026, we are seeing that BEC is now broader than email fraud. It is identity abuse at scale.
Even well-informed employees can be successfully deceived by highly convincing, business-relevant social engineering and a single authentic-looking file can lead to a serious compromise. As threat actors increasingly use AI to create even more convincing lures, we expect the risk of BEC and socially engineered attacks to remain high for European businesses.
Here are key lessons from this case that can help organisations keep from falling victim:
- Trust alone is not a security control. The user believed the files came from a trusted sender and even convinced others they were legitimate. Attackers increasingly exploit existing business relationships and realistic business opportunities.
- Legitimate-looking files can be malicious. The ZIP contained professional-looking documents, branding, and supporting files. The malware was hidden in a .scr (screensaver) file, which many users do not recognise as an executable.
- Social engineering can undermine technical controls. The user's confidence in the legitimacy of the files made it more difficult for the security team to properly review the incident and determine the best course of action.
- User awareness should focus on behaviour, not just file types. Employees should be suspicious of any request to open executable files, enter passwords to access content, or launch files outside normal business processes, even when the context appears genuine.
- Rapid response and trust in security alerts are critical. The organisation ultimately had to wipe the device because the threat reactivated after isolation was removed. Security teams need clear processes for handling disputes when users believe malicious content is legitimate.
Our investigation is ongoing, but this does not appear to be an isolated incident. Additional reports have been published detailing similar social engineering and BEC attacks. These cases also involved initial contact through a website form and well-crafted partnership proposals impersonating popular brands. Notably, the senders were reported to have used hyphenated lookalike domains of the brands they impersonated. This serves as another reminder to closely double check domain names before clicking any links and always take extra steps to verify new contacts, for example, by looking them up on Linkedin and the company website.

To learn more about the risk of BEC attacks, download our free Global Threat Landscape Report. And, if you believe your organisation may have fallen victim to a social engineering attack or would like to develop an effective cyber safe behaviour approach to help prevent these attacks, contact our experts today.
We are here for you
Need help with your cyber security or wondering how secure your business really is?
Get in touch and we will help you find the best solution.
