Contact company icon Add as a preferred source Download PDF version

In the RFQ cyber-attack, attackers disguise harmful malware as a ‘Request For Quote’ (RFQ), in order to encourage recipients to download dangerous files. This attack is an impersonation of a ‘Request For Quote’ (RFQ) from a legitimate, outside organisation. The attack originates from the throwaway address - [email protected], with the reply-to address - [email protected].

RFQ attack

By using urgent language, the attacker attempts to coax the recipient to click on the link ‘Rfq 507890.pdf’, without examining it for malicious content. Clicking on the link does not download a PDF or bring the recipient to an external website, but rather forces a malware download.

The downloaded file from the malicious link is a compressed .GZ file, which enables it to circumvent certain malware detectors

The downloaded file from the malicious link is a compressed .GZ file, which enables it to circumvent certain malware detectors. Within the compressed file is a text file, which is full of malicious code, including spyware, such as a key-logger.

If the recipient allows this code to run, the attacker could record everything that the recipient enters into his or her computer, or possibly even take complete control of the recipient’s device.

Bypass existing email security

Many security systems can only detect malware, if it is attached to an email in an uncompressed form. Putting malware into a .ZIP folder or a .GZ archive can easily circumvent these security measures. Abnormal Security prevented this attack, by recognising a number of signals, which when combined, flagged the email as malicious.

Some of these signals are contained in the message body, such as the presence of suspicious wording. Others are contained in the message headers, such as the fact that the reply-to address for this email did not match to the sender address or any of the links in the email. It is much more difficult for an attacker to hide these kinds of signals, than it is to hide the malware.

Summary of attack:

  • Platform: G Suite
  • Mailboxes: 500 - 1,000
  • Victims: Employees
  • Payload: Malicious Link
  • Technique: Impersonation

In case you missed it

Morse Watchmans enhances Lincoln's Inn security systems
Morse Watchmans enhances Lincoln's Inn security systems

The Honourable Society of Lincoln’s Inn is one of the four Inns of Court and operates as an active and thriving society of lawyers, sprawling across 11 acres in central Londo...

How are new technologies reshaping casino surveillance and security?
How are new technologies reshaping casino surveillance and security?

Casinos are tasked with monitoring vast gaming floors, cashier cages, and access points. The market for casino security and surveillance demands software and hardware that provide...

ASSA ABLOY at GSX 2026: Innovations in security
ASSA ABLOY at GSX 2026: Innovations in security

ASSA ABLOY will be exhibiting at Global Security Exchange (GSX) 2026 from September 14 - 16 at the Georgia World Congress Center in Atlanta, Georgia. The company invites attendees...