Common signs include unexpected Word attachments tied to HR, payroll, benefits, or bonus themes, especially when the filename looks legitimate but the file opens in recovery mode. Another warning is a QR code embedded in a branded document that sends users to a Microsoft 365 style login page. Delays between delivery and remediation can also indicate the campaign is active.
How corrupted file phishing is spotted in the wild
Corrupted file phishing usually stands out because the lure is built to look routine, not suspicious. Attackers lean on credible business themes, especially HR, payroll, benefits, and bonus updates, because those topics create enough urgency for users to open the attachment before checking the details.
The file itself often behaves oddly at open time. A document that looks like a normal Word attachment but opens in recovery mode, prompts repair, or shows formatting damage is a strong signal that the payload is not simply a malformed file, but a delivery mechanism designed to get the user past first-line suspicion.
A second common pattern is the use of a QR code embedded inside a branded document. The document appears legitimate at a glance, but the QR code shifts the victim to a Microsoft 365 style login page or another credential capture flow, which can bypass some email and URL inspection controls because the malicious destination is not visible until the code is scanned.
One of the most useful operational clues is timing. If delivery is followed by a noticeable delay before remediation, or if similar messages continue to circulate during that gap, it often indicates that the campaign is still active and the initial report has not yet disrupted the broader sending infrastructure.
What makes these lures effective against users and controls
Corrupted file phishing works because it exploits normal user behaviour around documents that appear relevant to work. People are more likely to trust a filename that matches a pay, policy, or benefits workflow, and they may ignore early warning signs when the content seems to come from a familiar business process.
The technique also tries to sidestep simple file-based trust checks. When a document is intentionally damaged or wrapped in a way that forces recovery behaviour, the file may still open far enough to display the lure while avoiding the clean signatures or previews that would make it easier to reject immediately.
Branded documents with QR codes create a second layer of deception. They borrow the appearance of normal corporate communication and then move the trust decision from the inbox to a mobile scan or browser login screen, where the real objective is often credential capture rather than malware delivery.
For teams that monitor mail and user reports, the key point is that the threat may not look like a classic attachment malware event. The observable symptoms are often social and behavioural first, then technical, which means triage has to consider both the document artefact and the follow-on login or token abuse path.
Practitioner guidance for triage and response
What to verify: Check whether the attachment was sent in a business context that would normally trigger action, then inspect whether the file opens in repair or recovery mode, contains an embedded QR code, or leads to a login page that mimics Microsoft 365. Those are higher-value indicators than the filename alone.
Decision rule: If the message combines a plausible HR or finance theme with an abnormal document open experience, treat it as a phishing event even before you confirm payload execution. If the content contains a QR code, assume the attacker is trying to move the victim off the mail channel and into a credential capture flow.
What to prioritise: Focus first on user exposure, message spread, and any sign that the same lure is still active across the tenant. The remediation question is not just whether one user reported it, but whether the campaign has already reached multiple inboxes or triggered follow-on sign-in activity.
Practitioner takeaway: The best signal is usually the combination of a believable work-themed lure, abnormal file behaviour, and a downstream login or scan path, not any single indicator on its own.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1566 — Phishing | Corrupted file lures are a phishing delivery method using deceptive attachments and links. |
| T1204 — User Execution | The attack depends on a user opening the corrupted document or scanning the embedded QR code. | |
| Recommendation — Map suspicious lures to T1566 and inspect messages for attachment-based delivery and follow-on credential capture. Correlate document open events and user interaction with the lure to confirm execution of the phishing chain. | ||
| CIS Controls v8 | 8 — Audit Log Management | Triage depends on message, sign-in, and remediation timing evidence across mail and identity logs. |
| Recommendation — Retain email, endpoint, and sign-in logs to reconstruct delivery, user interaction, and remediation timing. | ||
Related resources from NHI Mgmt Group
- What are the signs that an AiTM phishing kit is being used against an organisation?
- What are the signs that an organisation’s identity controls are failing against attacker-in-the-middle phishing?
- What are the signs that an organisation is falling behind on phishing resistant authentication?
- What are the signs that deepfake phishing is being used against an organization?