.. /.Iqy

Phishing
Double Click

Contributors:

mr.d0x

Description:

IQY or Internet Query Files are text files used by Excel to download data from the internet. It can be used by an attacker to execute remote commands on a machine.

OS:

Windows
Mac

Recommendation:

Block the download of IQY files.

Resources:

https://blog.knowbe4.com/new-phishing-campaign-uses-iqy-attachments-to-bypass-antivirus-and-installs-rats
https://blog.knowbe4.com/malicious-iqy-files-found-in-spam-campaign

File Samples: